Vulnerability index

Browse CVEs

7 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Rx4 1500 Firmware HIGH 8.8
CVE-2023-41031

Command injection in homemng.htm in Juplink RX4-1500 versions V1.0.2, V1.0.3, V1.0.4, and V1.0.5 allows remote authenticated attackers to execute com…

Mitigation only
Fix from $1,950 2023-09-22
Rx4 1500 Firmware HIGH 8.8
CVE-2023-41029

Command injection vulnerability in the homemng.htm endpoint in Juplink RX4-1500 Wifi router firmware versions V1.0.2, V1.0.3, V1.0.4, and V1.0.5 allo…

Mitigation only
Fix from $1,950 2023-09-22
Rx4 1500 Firmware HIGH 8.8
CVE-2023-41027

Credential disclosure in the '/webs/userpasswd.htm' endpoint in Juplink RX4-1500 Wifi router firmware versions V1.0.4 and V1.0.5 allows an authentica…

Mitigation only
Fix from $1,950 2023-09-22
Rx4 1500 Firmware CRITICAL 9.8
CVE-2023-41030

Hard-coded credentials in Juplink RX4-1500 versions V1.0.2 through V1.0.5 allow unauthenticated attackers to log in to the web interface or telnet se…

Fix: after 1.0.5
Fix from $2,300 2023-09-18
Rx4 1500 Firmware HIGH 8.8
CVE-2023-41028

A stack-based buffer overflow exists in Juplink RX4-1500, a WiFi router, in versions 1.0.2 through 1.0.5. An authenticated attacker can exploit this …

Fix: after 1.0.5
Fix from $1,950 2023-08-23
Rx4 1500 Firmware MEDIUM 5.5
CVE-2020-8798

httpd in Juplink RX4-1500 v1.0.3-v1.0.5 allows remote attackers to change or access router settings by connecting to the unauthenticated setup3.htm e…

Fix: after 1.0.5
Fix from $1,600 2020-04-23
Rx4 1500 Firmware MEDIUM 6.7
CVE-2020-8797

Juplink RX4-1500 v1.0.3 allows remote attackers to gain root access to the Linux subsystem via an unsanitized exec call (aka Command Line Injection),…

No fix yet
Fix from $1,600 2020-04-23