Vulnerability index

Browse CVEs

8 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Waybox Pro Firmware HIGH 8.8
CVE-2023-29120

Waybox Enel X web management application could be used to execute arbitrary OS commands and provide administrator’s privileges over the Waybox system.

Fix: 2.1.1.0_jb3vu096a+
Fix from $1,950 2024-11-05
Waybox Pro Firmware HIGH 8.8
CVE-2023-29121

Waybox Enel TCF Agent service could be used to get administrator’s privileges over the Waybox system.

Fix: 2.1.1.0_jb3vu096a+
Fix from $1,950 2024-11-05
Waybox Pro Firmware HIGH 8.8
CVE-2023-29126

The Waybox Enel X web management application contains a PHP-type juggling vulnerability that may allow a brute force process and under certain condit…

Fix: 2.1.1.0_jb3vu096a+
Fix from $1,950 2024-11-05
Waybox Pro Firmware HIGH 8.0
CVE-2023-29125

A heap buffer overflow could be triggered by sending a specific packet to TCP port 7700.

Fix: 2.1.1.0_jb3vu096a+
Fix from $1,950 2024-11-05
Waybox Pro Firmware HIGH 8.8
CVE-2023-29117

Waybox Enel X web management API authentication could be bypassed and provide administrator’s privileges over the Waybox system.

Fix: 2.1.1.0_jb3vu096a+
Fix from $1,950 2024-11-05
Waybox Pro Firmware HIGH 8.8
CVE-2023-29118

Waybox Enel X web management application could execute arbitrary requests on the internal database via /admin/versions.php.

Fix: 2.1.1.0_jb3vu096a+
Fix from $1,950 2024-11-05
Waybox Pro Firmware HIGH 8.8
CVE-2023-29119

Waybox Enel X web management application could execute arbitrary requests on the internal database via /admin/dbstore.php.

Fix: 2.1.1.0_jb3vu096a+
Fix from $1,950 2024-11-05
Waybox Pro Firmware MEDIUM 6.5
CVE-2023-29115

In certain conditions a request directed to the Waybox Enel X Web management application could cause a denial-of-service (e.g. reboot).

Fix: 2.1.1.0_jb3vu096a+
Fix from $1,600 2024-11-05