Vulnerability index

Browse CVEs

14 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.8 CVE-2023-49255 The router console is accessible without authentication at "data" field, and while a user needs to be logged in in order to modify the configuration,… H8951 4g Esp Firmware 2310271149+ Fix from $2,3002024-01-12 CRITICAL 9.8 CVE-2023-49262 The authentication mechanism can be bypassed by overflowing the value of the Cookie "authentication" field, provided there is an active user session. H8951 4g Esp Firmware 2310271149+ Fix from $2,3002024-01-12 HIGH 8.8 CVE-2023-49254 Authenticated user can execute arbitrary commands in the context of the root user by providing payload in the "destination" field of the network test… H8951 4g Esp Firmware 2310271149+ Fix from $1,9502024-01-12 HIGH 8.8 CVE-2023-49257 An authenticated user is able to upload an arbitrary CGI-compatible file using the certificate upload utility and execute it with the root user privi… H8951 4g Esp Firmware 2310271149+ Fix from $1,9502024-01-12 HIGH 7.5 CVE-2023-49256 It is possible to download the configuration backup without authorization and decrypt included passwords using hardcoded static key. H8951 4g Esp Firmware 2310271149+ Fix from $1,9502024-01-12 HIGH 7.5 CVE-2023-49259 The authentication cookies are generated using an algorithm based on the username, hardcoded secret and the up-time, and can be guessed in a reasonab… H8951 4g Esp Firmware 2310271149+ Fix from $1,9502024-01-12 HIGH 7.5 CVE-2023-49261 The "tokenKey" value used in user authorization is visible in the HTML source of the login page. H8951 4g Esp Firmware 2310271149+ Fix from $1,9502024-01-12 MEDIUM 6.1 CVE-2023-49258 User browser may be forced to execute JavaScript and pass the authentication cookie to the attacker leveraging the XSS vulnerability located at "/gui… H8951 4g Esp Firmware 2310271149+ Fix from $1,6002024-01-12 MEDIUM 6.1 CVE-2023-49260 An XSS attack can be performed by changing the MOTD banner and pointing the victim to the "terminal_tool.cgi" path. It can be used together with the … H8951 4g Esp Firmware 2310271149+ Fix from $1,6002024-01-12 CRITICAL 9.8 CVE-2023-49253 Root user password is hardcoded into the device and cannot be changed in the user interface. H8951 4g Esp Firmware 2310271149+ Fix from $2,3002024-01-12 CRITICAL 9.8 CVE-2021-28152EPSS 5% Hongdian H8922 3.0.5 devices have an undocumented feature that allows access to a shell as a superuser. To connect, the telnet service is used on por… H8922 Firmware No fix yet Fix from $2,3002021-05-06 HIGH 8.8 CVE-2021-28151EPSS 28% Hongdian H8922 3.0.5 devices allow OS command injection via shell metacharacters into the ip-address (aka Destination) field to the tools.cgi ping co… H8922 Firmware No fix yet Fix from $1,9502021-05-06 MEDIUM 6.5 CVE-2021-28149EPSS 16% Hongdian H8922 3.0.5 devices allow Directory Traversal. The /log_download.cgi log export handler does not validate user input and allows a remote att… H8922 Firmware No fix yet Fix from $1,6002021-05-06 MEDIUM 5.5 CVE-2021-28150 Hongdian H8922 3.0.5 devices allow the unprivileged guest user to read cli.conf (with the administrator password and other sensitive data) via /backu… H8922 Firmware No fix yet Fix from $1,6002021-05-06