Vulnerability index

Browse CVEs

135 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Fl Mguard 2102 Firmware HIGH 8.0
CVE-2024-43384

A low privileged remote attacker can gain the root password due to improper removal of sensitive information before storage or transfer.

Fix: 8.9.3 / 10.4.1+
Fix from $1,950 2026-05-07
Fl Nat 2008 Firmware HIGH 7.1
CVE-2025-41748EPSS 10%

An XSS vulnerability in pxc_Dot1xCfg.php can be used by an unauthenticated remote attacker to trick an authenticated user to click on the link provid…

Fix: 3.50+
Fix from $1,950 2025-12-09
Fl Switch 2008f Firmware HIGH 7.1
CVE-2025-41749

An XSS vulnerability in port_util.php can be used by an unauthenticated remote attacker to trick an authenticated user to click on the link provided …

Fix: 3.50+
Fix from $1,950 2025-12-09
Fl Switch 2008f Firmware HIGH 7.1
CVE-2025-41750EPSS 10%

An XSS vulnerability in pxc_PortCfg.php can be used by an unauthenticated remote attacker to trick an authenticated user to click on the link provide…

Fix: 3.50+
Fix from $1,950 2025-12-09
Fl Nat 2008 Firmware HIGH 7.1
CVE-2025-41751EPSS 10%

An XSS vulnerability in pxc_portCntr.php can be used by an unauthenticated remote attacker to trick an authenticated user to click on the link provid…

Fix: 3.50+
Fix from $1,950 2025-12-09
Fl Nat 2008 Firmware HIGH 7.1
CVE-2025-41752EPSS 10%

An XSS vulnerability in pxc_portSfp.php can be used by an unauthenticated remote attacker to trick an authenticated user to click on the link provide…

Fix: 3.50+
Fix from $1,950 2025-12-09
Fl Nat 2008 Firmware HIGH 7.1
CVE-2025-41745

An XSS vulnerability in pxc_portCntr2.php can be used by an unauthenticated remote attacker to trick an authenticated user to send a manipulated POST…

Fix: 3.50+
Fix from $1,950 2025-12-09
Fl Switch 2406 2sfx Pn Firmware HIGH 7.1
CVE-2025-41746EPSS 10%

An XSS vulnerability in pxc_portSecCfg.php can be used by an unauthenticated remote attacker to trick an authenticated user to send a manipulated POS…

Fix: 3.50+
Fix from $1,950 2025-12-09
Fl Nat 2008 Firmware HIGH 7.1
CVE-2025-41747EPSS 10%

An XSS vulnerability in pxc_vlanIntfCfg.php can be used by an unauthenticated remote attacker to trick an authenticated user to send a manipulated PO…

Fix: 3.50+
Fix from $1,950 2025-12-09
Fl Switch 2708 Pn Firmware MEDIUM 6.8
CVE-2025-41697

An attacker can use an undocumented UART port on the PCB as a side-channel to get root access e.g. with the credentials obtained from CVE-2025-416…

Fix: 3.50+
Fix from $1,600 2025-12-09
Fl Nat 2008 Firmware HIGH 7.1
CVE-2025-41695

An XSS vulnerability in dyn_conn.php can be used by an unauthenticated remote attacker to trick an authenticated user to send a manipulated POST requ…

Fix: 3.50+
Fix from $1,950 2025-12-09
Fl Switch 2708 Pn Firmware MEDIUM 6.8
CVE-2025-41692

A high privileged remote attacker with admin privileges for the webUI can brute-force the "root" and "user" passwords of the underlying OS due to a w…

Fix: 3.50+
Fix from $1,600 2025-12-09
Fl Switch 2708 Pn Firmware MEDIUM 6.5
CVE-2025-41694

A low privileged remote attacker can run the webshell with an empty command containing whitespace. The server will then block until it receives more …

Fix: 3.50+
Fix from $1,600 2025-12-09
Charx Sec 3000 Firmware CRITICAL 9.8
CVE-2025-25270

An unauthenticated remote attacker can alter the device configuration in a way to get remote code execution as root with specific configurations.

Fix: 1.7.3+
Fix from $2,300 2025-07-08
Charx Sec 3000 Firmware HIGH 8.8
CVE-2025-25271

An unauthenticated adjacent attacker is able to configure a new OCPP backend, due to insecure defaults for the configuration interface.

Fix: 1.7.3+
Fix from $1,950 2025-07-08
Charx Sec 3000 Firmware HIGH 8.8
CVE-2025-25268

An unauthenticated adjacent attacker can modify configuration by sending specific requests to an API-endpoint resulting in read and write access due …

Fix: 1.7.3+
Fix from $1,950 2025-07-08
Charx Sec 3000 Firmware HIGH 8.4
CVE-2025-25269

An unauthenticated local attacker can inject a command that is subsequently executed as root, leading to a privilege escalation.

Fix: 1.7.3+
Fix from $1,950 2025-07-08
Charx Sec 3000 Firmware HIGH 7.8
CVE-2025-24005

A local attacker with a local user account can leverage a vulnerable script via SSH to escalate privileges to root due to improper input validation.

Fix: 1.7.3+
Fix from $1,950 2025-07-08
Charx Sec 3000 Firmware HIGH 7.8
CVE-2025-24006

A low privileged local attacker can leverage insecure permissions via SSH on the affected devices to escalate privileges to root.

Fix: 1.7.3+
Fix from $1,950 2025-07-08
Charx Sec 3000 Firmware MEDIUM 5.2
CVE-2025-24004

A physical attacker with access to the device display via USB-C can send a message to the device which triggers an unsecure copy to a buffer resultin…

Fix: after 1.6.5
Fix from $1,600 2025-07-08
Charx Sec 3000 Firmware HIGH 8.2
CVE-2025-24003

An unauthenticated remote attacker can use MQTT messages to trigger out-of-bounds writes in charging stations complying with German Calibration Law, …

Fix: after 1.6.5
Fix from $1,950 2025-07-08
Charx Sec 3000 Firmware MEDIUM 5.3
CVE-2025-24002

An unauthenticated remote attacker can use MQTT messages to crash a service on charging stations complying with German Calibration Law, resulting in …

Fix: after 1.6.5
Fix from $1,600 2025-07-08
Tc Mguard Rs4000 4g Vzw Vpn Firmware HIGH 8.8
CVE-2024-7699

An low privileged remote attacker can execute OS commands with root privileges due to improper neutralization of special elements in user data.

Fix: 8.9.3+
Fix from $1,950 2024-09-10
Tc Mguard Rs4000 4g Vzw Vpn Firmware HIGH 8.1
CVE-2024-43392

A low privileged remote attacker can perform configuration changes of the firewall services, including packet filter, packet forwarding, network acce…

Fix: 8.9.3+
Fix from $1,950 2024-09-10
Tc Mguard Rs4000 4g Vzw Vpn Firmware HIGH 8.1
CVE-2024-43393

A low privileged remote attacker can perform configuration changes of the firewall services, including packet filter, packet forwarding, network acce…

Fix: 8.9.3+
Fix from $1,950 2024-09-10
Tc Mguard Rs4000 4g Vzw Vpn Firmware MEDIUM 5.7
CVE-2024-7698

A low privileged remote attacker can get access to CSRF tokens of higher privileged users which can be abused to mount CSRF attacks.

Fix: 8.9.3+
Fix from $1,600 2024-09-10
Tc Mguard Rs4000 4g Vzw Vpn Firmware HIGH 8.1
CVE-2024-43389

A low privileged remote attacker can perform configuration changes of the ospf service through OSPF_INTERFACE.SIMPLE_KEY, OSPF_INTERFACE.DIGEST_KEY e…

Fix: 8.9.3+
Fix from $1,950 2024-09-10
Tc Mguard Rs4000 4g Vzw Vpn Firmware HIGH 8.1
CVE-2024-43390

A low privileged remote attacker can perform configuration changes of the firewall services, including packet forwarding or NAT through the FW_NAT.IN…

Fix: 8.9.3+
Fix from $1,950 2024-09-10
Tc Mguard Rs4000 4g Vzw Vpn Firmware HIGH 8.1
CVE-2024-43391

A low privileged remote attacker can perform configuration changes of the firewall services, including packet filter, packet forwarding, network acce…

Fix: 8.9.3+
Fix from $1,950 2024-09-10
Tc Mguard Rs4000 4g Vzw Vpn Firmware HIGH 8.8
CVE-2024-43385

A low privileged remote attacker can trigger the execution of arbitrary OS commands as root due to improper neutralization of special elements in the…

Fix: 8.9.3+
Fix from $1,950 2024-09-10