Vulnerability index

Browse CVEs

10 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Gryphon Tower Firmware CRITICAL 9.8
CVE-2021-20146

An unprotected ssh private key exists on the Gryphon devices which could be used to achieve root access to a server affiliated with Gryphon's develop…

Fix: after 04.0004.12
Fix from $2,300 2021-12-09
Gryphon Tower Firmware HIGH 8.8
CVE-2021-20143

An unauthenticated command injection vulnerability exists in the parameters of operation 48 in the controller_server service on Gryphon Tower routers…

Fix: after 04.0004.12
Fix from $1,950 2021-12-09
Gryphon Tower Firmware HIGH 8.8
CVE-2021-20144

An unauthenticated command injection vulnerability exists in the parameters of operation 49 in the controller_server service on Gryphon Tower routers…

Fix: after 04.0004.12
Fix from $1,950 2021-12-09
Gryphon Tower Firmware HIGH 7.5
CVE-2021-20145

Gryphon Tower routers contain an unprotected openvpn configuration file which can grant attackers access to the Gryphon homebound VPN network which e…

Fix: after 04.0004.12
Fix from $1,950 2021-12-09
Gryphon Tower Firmware HIGH 8.8
CVE-2021-20138

An unauthenticated command injection vulnerability exists in multiple parameters in the Gryphon Tower router’s web interface at /cgi-bin/luci/rc. An …

Fix: after 04.0004.12
Fix from $1,950 2021-12-09
Gryphon Tower Firmware HIGH 8.8
CVE-2021-20139

An unauthenticated command injection vulnerability exists in the parameters of operation 3 in the controller_server service on Gryphon Tower routers.…

Fix: after 04.0004.12
Fix from $1,950 2021-12-09
Gryphon Tower Firmware HIGH 8.8
CVE-2021-20140

An unauthenticated command injection vulnerability exists in the parameters of operation 10 in the controller_server service on Gryphon Tower routers…

Fix: after 04.0004.12
Fix from $1,950 2021-12-09
Gryphon Tower Firmware HIGH 8.8
CVE-2021-20141

An unauthenticated command injection vulnerability exists in the parameters of operation 32 in the controller_server service on Gryphon Tower routers…

Fix: after 04.0004.12
Fix from $1,950 2021-12-09
Gryphon Tower Firmware HIGH 8.8
CVE-2021-20142

An unauthenticated command injection vulnerability exists in the parameters of operation 41 in the controller_server service on Gryphon Tower routers…

Fix: after 04.0004.12
Fix from $1,950 2021-12-09
Gryphon Tower Firmware MEDIUM 6.1
CVE-2021-20137

A reflected cross-site scripting vulnerability exists in the url parameter of the /cgi-bin/luci/site_access/ page on the Gryphon Tower router's web i…

Fix: after 04.0004.12
Fix from $1,600 2021-12-09