Vulnerability index

Browse CVEs

19 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Lvskihp Indoorunit Firmware CRITICAL 9.8
CVE-2022-28369

Verizon 5G Home LVSKIHP InDoorUnit (IDU) 3.4.66.162 does not validate the user-provided URL within the crtcmode function's enable_ssh sub-operation o…

No fix yet
Fix from $2,300 2022-07-14
Lvskihp Indoorunit Firmware CRITICAL 9.8
CVE-2022-28373

Verizon 5G Home LVSKIHP InDoorUnit (IDU) 3.4.66.162 does not properly sanitize user-controlled parameters within the crtcreadpartition function of th…

No fix yet
Fix from $2,300 2022-07-14
Lvskihp Outdoorunit Firmware CRITICAL 9.8
CVE-2022-28375

Verizon 5G Home LVSKIHP OutDoorUnit (ODU) 3.33.101.0 does not property sanitize user-controlled parameters within the crtcswitchsimprofile function o…

No fix yet
Fix from $2,300 2022-07-14
Lvskihp Outdoorunit Firmware HIGH 8.8
CVE-2022-28374

Verizon 5G Home LVSKIHP OutDoorUnit (ODU) 3.33.101.0 does not property sanitize user-controlled parameters within the DMACC URLs on the Settings page…

No fix yet
Fix from $1,950 2022-07-14
Lvskihp Outdoorunit Firmware HIGH 7.5
CVE-2022-28370

On Verizon 5G Home LVSKIHP OutDoorUnit (ODU) 3.33.101.0 devices, the RPC endpoint crtc_fw_upgrade provides a means of provisioning a firmware update …

No fix yet
Fix from $1,950 2022-07-14
Lvskihp Indoorunit Firmware HIGH 7.5
CVE-2022-28371

On Verizon 5G Home LVSKIHP InDoorUnit (IDU) 3.4.66.162 and OutDoorUnit (ODU) 3.33.101.0 devices, the CRTC and ODU RPC endpoints rely on a static cert…

No fix yet
Fix from $1,950 2022-07-14
Lvskihp Indoorunit Firmware HIGH 7.5
CVE-2022-28372

On Verizon 5G Home LVSKIHP InDoorUnit (IDU) 3.4.66.162 and OutDoorUnit (ODU) 3.33.101.0 devices, the CRTC and ODU RPC endpoints provide a means of pr…

No fix yet
Fix from $1,950 2022-07-14
Lvskihp Indoorunit Firmware HIGH 7.5
CVE-2022-28377

On Verizon 5G Home LVSKIHP InDoorUnit (IDU) 3.4.66.162 and OutDoorUnit (ODU) 3.33.101.0 devices, the CRTC and ODU RPC endpoints rely on a static acco…

No fix yet
Fix from $1,950 2022-07-14
4g Lte Network Extender Firmware HIGH 7.5
CVE-2022-29729

Verizon 4G LTE Network Extender GA4.38 - V0.4.038.2131 utilizes a weak default admin password generation algorithm which generates passwords that are…

No fix yet
Fix from $1,950 2022-06-02
Lvskihp Firmware HIGH 8.1
CVE-2022-28376

Verizon 5G Home LVSKIHP outside devices through 2022-02-15 allow anyone (knowing the device's serial number) to access a CPE admin website, e.g., at …

Fix: after 2022-02-15
Fix from $1,950 2022-04-03
Serialize Javascript HIGH 8.1
CVE-2020-7660

serialize-javascript prior to 3.1.0 allows remote attackers to inject arbitrary code via the function "deleteFunctions" within "index.js".

Fix: 3.1.0+
Fix from $1,950 2020-06-01
Serialize Javascript MEDIUM 5.4
CVE-2019-16769

The serialize-javascript npm package before version 2.1.1 is vulnerable to Cross-site Scripting (XSS). It does not properly mitigate against unsafe c…

Fix: 2.1.1+
Fix from $1,600 2019-12-05
Fios Quantum Gateway G1100 Firmware HIGH 7.5
CVE-2019-3916

Information disclosure vulnerability in Verizon Fios Quantum Gateway (G1100) firmware version 02.01.00.05 allows an remote, unauthenticated attacker …

Mitigation only
Fix from $1,950 2019-04-11
Fios Quantum Gateway G1100 Firmware HIGH 7.5
CVE-2019-3915

Authentication Bypass by Capture-replay vulnerability in Verizon Fios Quantum Gateway (G1100) firmware version 02.01.00.05 allows an unauthenticated …

Mitigation only
Fix from $1,950 2019-04-11
Fios Quantum Gateway G1100 Firmware HIGH 7.2
CVE-2019-3914EPSS 30%

Remote command injection vulnerability in Verizon Fios Quantum Gateway (G1100) firmware version 02.01.00.05 allows a remote, authenticated attacker t…

No fix yet
Fix from $1,950 2019-04-11
Wireless Network Extender MEDIUM 6.2
CVE-2013-4874

The Uboot bootloader on the Verizon Wireless Network Extender SCS-26UC4 allows physically proximate attackers to obtain root access by connecting a c…

Mitigation only
Fix from $1,600 2013-07-18
Wireless Network Extender MEDIUM 6.2
CVE-2013-4875

The Uboot bootloader on the Verizon Wireless Network Extender SCS-2U01 allows physically proximate attackers to bypass the intended boot process and …

Mitigation only
Fix from $1,600 2013-07-18
Wireless Network Extender MEDIUM 6.2
CVE-2013-4876

The Verizon Wireless Network Extender SCS-2U01 has a hardcoded password for the root account, which makes it easier for physically proximate attacker…

Mitigation only
Fix from $1,600 2013-07-18
Fios Actiontec Mi424wr Gen31 Router Firmware MEDIUM 6.8
CVE-2013-0126

Multiple cross-site request forgery (CSRF) vulnerabilities in index.cgi on the Verizon FIOS Actiontec MI424WR-GEN3I router with firmware 40.19.36 all…

No fix yet
Fix from $1,600 2013-03-21