Vulnerability index

Browse CVEs

14 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Smart Reader Firmware CRITICAL 9.8
CVE-2023-40146

A privilege escalation vulnerability exists in the /bin/login functionality of Peplink Smart Reader v1.2.0 (in QEMU). A specially crafted command lin…

No fix yet
Fix from $2,300 2024-04-17
Smart Reader Firmware HIGH 8.8
CVE-2023-45744

A data integrity vulnerability exists in the web interface /cgi-bin/upload_config.cgi functionality of Peplink Smart Reader v1.2.0 (in QEMU). A speci…

No fix yet
Fix from $1,950 2024-04-17
Smart Reader Firmware HIGH 7.5
CVE-2023-43491

An information disclosure vulnerability exists in the web interface /cgi-bin/debug_dump.cgi functionality of Peplink Smart Reader v1.2.0 (in QEMU). A…

No fix yet
Fix from $1,950 2024-04-17
Smart Reader Firmware HIGH 7.5
CVE-2023-45209

An information disclosure vulnerability exists in the web interface /cgi-bin/download_config.cgi functionality of Peplink Smart Reader v1.2.0 (in QEM…

No fix yet
Fix from $1,950 2024-04-17
Smart Reader Firmware HIGH 7.2
CVE-2023-39367EPSS 38%

An OS command injection vulnerability exists in the web interface mac2name functionality of Peplink Smart Reader v1.2.0 (in QEMU). A specially crafte…

No fix yet
Fix from $1,950 2024-04-17
Surf Soho Firmware HIGH 8.8
CVE-2023-34356EPSS 6%

An OS command injection vulnerability exists in the data.cgi xfer_dns functionality of peplink Surf SOHO HW1 v6.3.5 (in QEMU). A specially crafted HT…

No fix yet
Fix from $1,950 2023-10-11
Surf Soho Firmware HIGH 8.8
CVE-2023-35193EPSS 6%

An OS command injection vulnerability exists in the api.cgi cmd.mvpn.x509.write functionality of peplink Surf SOHO HW1 v6.3.5 (in QEMU). A specially …

No fix yet
Fix from $1,950 2023-10-11
Surf Soho Firmware HIGH 8.8
CVE-2023-35194EPSS 6%

An OS command injection vulnerability exists in the api.cgi cmd.mvpn.x509.write functionality of peplink Surf SOHO HW1 v6.3.5 (in QEMU). A specially …

No fix yet
Fix from $1,950 2023-10-11
Surf Soho Firmware MEDIUM 5.4
CVE-2023-34354

A stored cross-site scripting (XSS) vulnerability exists in the upload_brand.cgi functionality of peplink Surf SOHO HW1 v6.3.5 (in QEMU). A specially…

No fix yet
Fix from $1,600 2023-10-11
Surf Soho Firmware HIGH 8.8
CVE-2023-27380EPSS 6%

An OS command injection vulnerability exists in the admin.cgi USSD_send functionality of peplink Surf SOHO HW1 v6.3.5 (in QEMU). A specially crafted …

No fix yet
Fix from $1,950 2023-10-11
Surf Soho Firmware HIGH 8.8
CVE-2023-28381EPSS 6%

An OS command injection vulnerability exists in the admin.cgi MVPN_trial_init functionality of peplink Surf SOHO HW1 v6.3.5 (in QEMU). A specially cr…

No fix yet
Fix from $1,950 2023-10-11
B305hw2 Firmware HIGH 8.8
CVE-2017-8836

CSRF exists on Peplink Balance 305, 380, 580, 710, 1350, and 2500 devices with firmware before fw-b305hw2_380hw6_580hw2_710hw3_1350hw2_2500-7.0.1-bui…

No fix yet
Fix from $1,950 2017-06-05
B305hw2 Firmware HIGH 8.1
CVE-2017-8841

Arbitrary file deletion exists on Peplink Balance 305, 380, 580, 710, 1350, and 2500 devices with firmware before fw-b305hw2_380hw6_580hw2_710hw3_135…

No fix yet
Fix from $1,950 2017-06-05
B305hw2 Firmware MEDIUM 6.1
CVE-2017-8839

XSS via orig_url exists on Peplink Balance 305, 380, 580, 710, 1350, and 2500 devices with firmware before fw-b305hw2_380hw6_580hw2_710hw3_1350hw2_25…

No fix yet
Fix from $1,600 2017-06-05