Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
CRITICAL 9.8
CVE-2023-49255
The router console is accessible without authentication at "data" field, and while a user needs to be logged in in order to modify the configuration,…
H8951 4g Esp Firmware
2310271149+
CRITICAL 9.8
CVE-2023-49262
The authentication mechanism can be bypassed by overflowing the value of the Cookie "authentication" field, provided there is an active user session.
H8951 4g Esp Firmware
2310271149+
HIGH 8.8
CVE-2023-49254
Authenticated user can execute arbitrary commands in the context of the root user by providing payload in the "destination" field of the network test…
H8951 4g Esp Firmware
2310271149+
HIGH 8.8
CVE-2023-49257
An authenticated user is able to upload an arbitrary CGI-compatible file using the certificate upload utility and execute it with the root user privi…
H8951 4g Esp Firmware
2310271149+
HIGH 7.5
CVE-2023-49256
It is possible to download the configuration backup without authorization and decrypt included passwords using hardcoded static key.
H8951 4g Esp Firmware
2310271149+
HIGH 7.5
CVE-2023-49259
The authentication cookies are generated using an algorithm based on the username, hardcoded secret and the up-time, and can be guessed in a reasonab…
H8951 4g Esp Firmware
2310271149+
HIGH 7.5
CVE-2023-49261
The "tokenKey" value used in user authorization is visible in the HTML source of the login page.
H8951 4g Esp Firmware
2310271149+
MEDIUM 6.1
CVE-2023-49258
User browser may be forced to execute JavaScript and pass the authentication cookie to the attacker leveraging the XSS vulnerability located at "/gui…
H8951 4g Esp Firmware
2310271149+
MEDIUM 6.1
CVE-2023-49260
An XSS attack can be performed by changing the MOTD banner and pointing the victim to the "terminal_tool.cgi" path. It can be used together with the …
H8951 4g Esp Firmware
2310271149+
CRITICAL 9.8
CVE-2023-49253
Root user password is hardcoded into the device and cannot be changed in the user interface.
H8951 4g Esp Firmware
2310271149+
CRITICAL 9.8
CVE-2021-28152EPSS 5%
Hongdian H8922 3.0.5 devices have an undocumented feature that allows access to a shell as a superuser. To connect, the telnet service is used on por…
H8922 Firmware
No fix yet
HIGH 8.8
CVE-2021-28151EPSS 28%
Hongdian H8922 3.0.5 devices allow OS command injection via shell metacharacters into the ip-address (aka Destination) field to the tools.cgi ping co…
H8922 Firmware
No fix yet
MEDIUM 6.5
CVE-2021-28149EPSS 16%
Hongdian H8922 3.0.5 devices allow Directory Traversal. The /log_download.cgi log export handler does not validate user input and allows a remote att…
H8922 Firmware
No fix yet
MEDIUM 5.5
CVE-2021-28150
Hongdian H8922 3.0.5 devices allow the unprivileged guest user to read cli.conf (with the administrator password and other sensitive data) via /backu…
H8922 Firmware
No fix yet