Vulnerability index

Browse CVEs

27 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Arris Surfboard Sbg6950ac2 Firmware CRITICAL 9.8
CVE-2024-23618

An arbitrary code execution vulnerability exists in Arris SURFboard SGB6950AC2 devices. An unauthenticated attacker can exploit this vulnerability to…

Mitigation only
Fix from $2,300 2024-01-26
Dg3450 Firmware MEDIUM 6.1
CVE-2023-27572

An issue was discovered in CommScope Arris DG3450 Cable Gateway AR01.02.056.18_041520_711.NCS.10. A reflected XSS vulnerability was discovered in the…

No fix yet
Fix from $1,600 2023-04-15
Dg3450 Firmware MEDIUM 5.3
CVE-2023-27571

An issue was discovered in DG3450 Cable Gateway AR01.02.056.18_041520_711.NCS.10. The troubleshooting_logs_download.php log file download functionali…

No fix yet
Fix from $1,600 2023-04-15
Arris Tr3300 Firmware CRITICAL 9.8
CVE-2022-26996

Arris TR3300 v1.0.13 was discovered to contain a command injection vulnerability in the pppoe function via the pppoe_username, pppoe_passwd, and pppo…

No fix yet
Fix from $2,300 2022-03-15
Arris Tr3300 Firmware CRITICAL 9.8
CVE-2022-26997

Arris TR3300 v1.0.13 was discovered to contain a command injection vulnerability in the upnp function via the upnp_ttl parameter. This vulnerability …

No fix yet
Fix from $2,300 2022-03-15
Arris Tr3300 Firmware CRITICAL 9.8
CVE-2022-26998

Arris TR3300 v1.0.13 was discovered to contain a command injection vulnerability in the wps setting function via the wps_enrolee_pin parameter. This …

No fix yet
Fix from $2,300 2022-03-15
Arris Tr3300 Firmware CRITICAL 9.8
CVE-2022-26999

Arris TR3300 v1.0.13 was discovered to contain a command injection vulnerability in the static ip settings function via the wan_ip_stat, wan_mask_sta…

No fix yet
Fix from $2,300 2022-03-15
Arris Tr3300 Firmware CRITICAL 9.8
CVE-2022-27000

Arris TR3300 v1.0.13 was discovered to contain a command injection vulnerability in the time and time zone function via the h_primary_ntp_server, h_b…

No fix yet
Fix from $2,300 2022-03-15
Arris Tr3300 Firmware CRITICAL 9.8
CVE-2022-27001

Arris TR3300 v1.0.13 were discovered to contain a command injection vulnerability in the dhcp function via the hostname parameter. This vulnerability…

No fix yet
Fix from $2,300 2022-03-15
Arris Tr3300 Firmware CRITICAL 9.8
CVE-2022-27002EPSS 5%

Arris TR3300 v1.0.13 were discovered to contain a command injection vulnerability in the ddns function via the ddns_name, ddns_pwd, h_ddns、ddns_host…

No fix yet
Fix from $2,300 2022-03-15
Arris Tr3300 Firmware CRITICAL 9.8
CVE-2022-26995

Arris TR3300 v1.0.13 was discovered to contain a command injection vulnerability in the pptp (wan_pptp.html) function via the pptp_fix_ip, pptp_fix_m…

No fix yet
Fix from $2,300 2022-03-15
Arris Surfboard Sbg6950ac2 Firmware HIGH 8.8
CVE-2021-41552

CommScope SURFboard SBG6950AC2 9.1.103AA23 devices allow Command Injection.

Mitigation only
Fix from $1,950 2022-02-15
Arris Surfboard Sb8200 Firmware HIGH 7.1
CVE-2021-20119

The password change utility for the Arris SurfBoard SB8200 can have safety measures bypassed that allow any logged-in user to change the administrato…

No fix yet
Fix from $1,950 2021-11-09
Arris Surfboard Sb8200 Firmware HIGH 8.8
CVE-2021-20120

The administration web interface for the Arris Surfboard SB8200 lacks any protections against cross-site request forgery attacks. This means that an …

No fix yet
Fix from $1,950 2021-10-21
Ruckus Zoneflex R500 Firmware HIGH 8.8
CVE-2020-8830

CSRF in login.asp on Ruckus devices allows an attacker to access the panel, and use SSRF to perform scraping or other analysis via the SUBCA-1 field …

No fix yet
Fix from $1,950 2020-05-05
Ruckus Zoneflex R500 Firmware HIGH 8.1
CVE-2020-7983

A CSRF issue in login.asp on Ruckus R500 3.4.2.0.384 devices allows remote attackers to access the panel or conduct SSRF attacks.

No fix yet
Fix from $1,950 2020-05-05
Ruckus Zoneflex R500 Firmware MEDIUM 6.1
CVE-2020-8033

Ruckus R500 3.4.2.0.384 devices allow XSS via the index.asp Device Name field.

No fix yet
Fix from $1,600 2020-05-05
Arris Tg1692a Firmware HIGH 7.5
CVE-2020-9476

ARRIS TG1692A devices allow remote attackers to discover the administrator login name and password by reading the /login page and performing base64 d…

Mitigation only
Fix from $1,950 2020-03-04
Tr4400 Firmware CRITICAL 9.8
CVE-2019-15805

CommScope ARRIS TR4400 devices with firmware through A1.00.004-180301 are vulnerable to an authentication bypass to the administrative interface beca…

Mitigation only
Fix from $2,300 2019-08-29
Tr4400 Firmware CRITICAL 9.8
CVE-2019-15806

CommScope ARRIS TR4400 devices with firmware through A1.00.004-180301 are vulnerable to an authentication bypass to the administrative interface beca…

Mitigation only
Fix from $2,300 2019-08-29
Arris Dg950a Firmware CRITICAL 9.8
CVE-2018-20383

ARRIS DG950A 7.10.145 and DG950S 7.10.145.EURO devices allow remote attackers to discover credentials via iso.3.6.1.4.1.4491.2.4.1.1.6.1.1.0 and iso.…

No fix yet
Fix from $2,300 2018-12-23
Arris Sbg6580 2 Firmware CRITICAL 9.8
CVE-2018-20386

ARRIS SBG6580-2 D30GW-SEAEAGLE-1.5.2.5-GA-00-NOSH devices allow remote attackers to discover credentials via iso.3.6.1.4.1.4491.2.4.1.1.6.1.1.0 and i…

No fix yet
Fix from $2,300 2018-12-23
Arris Tg2492lg Na Firmware HIGH 7.5
CVE-2018-17555

The web component on ARRIS TG2492LG-NA 061213 devices allows remote attackers to obtain sensitive information via the /snmpGet oids parameter.

No fix yet
Fix from $1,950 2018-09-26
Arris Tg1682g Firmware HIGH 8.0
CVE-2018-10990

On Arris Touchstone Telephony Gateway TG1682G 9.1.103J6 devices, a logout action does not immediately destroy all state on the device related to the …

Mitigation only
Fix from $1,950 2018-05-14
Arris Tg1682g Firmware MEDIUM 6.6
CVE-2018-10989

Arris Touchstone Telephony Gateway TG1682G 9.1.103J6 devices are distributed by some ISPs with a default password of "password" for the admin account…

Mitigation only
Fix from $1,600 2018-05-14
Arris Tg1682g Firmware MEDIUM 6.1
CVE-2017-16836

Arris TG1682G devices with Comcast TG1682_2.0s7_PRODse 10.0.59.SIP.PC20.CT software allow Unauthenticated Stored XSS via the actionHandler/ajax_manag…

No fix yet
Fix from $1,600 2017-11-16
Arris Sbg901 MEDIUM 6.8
CVE-2014-3778

Multiple cross-site request forgery (CSRF) vulnerabilities in goform/RgDdns in ARRIS (formerly Motorola) SBG901 SURFboard Wireless Cable Modem allow …

No fix yet
Fix from $1,600 2014-06-19