3303 vulnerabilidades · Networking Orden: CVSS EPSS Año ID
CVE-2017-7343
Fortinet FortiPortal Networking
N/A
UNKNOWN
EPSS
0.3%
2017 1 PoC

An open redirect vulnerability in Fortinet FortiPortal 4.0.0 and below allows attacker to execute unauthorized code or commands via the url parameter.

CVE-2017-6127
Software Genérico Web Networking
N/A
UNKNOWN
EPSS
0.2%
2017 1 PoC

Multiple cross-site request forgery (CSRF) vulnerabilities in the access portal on the DIGISOL DG-HR1400 Wireless Router with firmware 1.00.02 allow remote attackers to hijack the authentication of administrators for requests that (1) change the SSID, (2) change the Wi-Fi password, or (3) possibly have unspecified other impact via crafted requests to form2WlanBasicSetup.cgi.

CVE-2017-13772
Software Genérico Networking
N/A
UNKNOWN
EPSS
52.7%
2017 3 PoCs

Multiple stack-based buffer overflows in TP-Link WR940N WiFi routers with hardware version 4 allow remote authenticated users to execute arbitrary code via the (1) ping_addr parameter to PingIframeRpm.htm or (2) dnsserver2 parameter to WanStaticIpV6CfgRpm.htm.

CVE-2017-1000064
Software Genérico Networking
N/A
UNKNOWN
EPSS
0.4%
2017 1 PoC

kittoframework kitto version 0.5.1 is vulnerable to memory exhaustion in the router resulting in DoS

CVE-2007-3038
Software Genérico Networking Windows
N/A
UNKNOWN
EPSS
30.6%
2007 1 PoC

The Teredo interface in Microsoft Windows Vista and Vista x64 Edition does not properly handle certain network traffic, which allows remote attackers to bypass firewall blocking rules and obtain sensitive information via crafted IPv6 traffic, aka "Windows Vista Firewall Blocking Rule Information Disclosure Vulnerability."

CVE-2014-9143
Software Genérico Networking
N/A
UNKNOWN
EPSS
3.6%
2014 1 PoC

Open redirect vulnerability in Technicolor Router TD5130 with firmware 2.05.C29GV allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the failrefer parameter.

CVE-2015-2839
Software Genérico Web Networking
N/A
UNKNOWN
EPSS
0.4%
2015 3 PoCs

The Nitro API in Citrix NetScaler before 10.5 build 52.3nc uses an incorrect Content-Type when returning an error message, which allows remote attackers to conduct cross-site scripting (XSS) attacks via the file_name JSON member in params/xen_hotfix/0 to nitro/v1/config/xen_hotfix.

CVE-2024-45030
Linux Web Networking
N/A
UNKNOWN
EPSS
0.0%
2024 1 PoC

In the Linux kernel, the following vulnerability has been resolved: igb: cope with large MAX_SKB_FRAGS Sabrina reports that the igb driver does not cope well with large MAX_SKB_FRAG values: setting MAX_SKB_FRAG to 45 causes payload corruption on TX. An easy reproducer is to run ssh to connect to the machine. With MAX_SKB_FRAGS=17 it works, with MAX_SKB_FRAGS=45 it fails. This has been reported originally in https://bugzilla.redhat.com/show_bug.cgi?id=2265320 The root cause of the issue is that the driver does not take into account properly the (possibly large) shared info size when selec

CVE-2017-3807
Cisco ASA Software with Clientless SSL VPN portal is enabled Major Releases 9.0-9.6 Networking
N/A
UNKNOWN
EPSS
11.4%
2017 CWE-119 1 PoC

A vulnerability in Common Internet Filesystem (CIFS) code in the Clientless SSL VPN functionality of Cisco ASA Software, Major Releases 9.0-9.6, could allow an authenticated, remote attacker to cause a heap overflow. The vulnerability is due to insufficient validation of user supplied input. An attacker could exploit this vulnerability by sending a crafted URL to the affected system. An exploit could allow the remote attacker to cause a reload of the affected system or potentially execute code. Note: Only traffic directed to the affected system can be used to exploit this vulnerability. This v

CVE-2017-3132
Fortinet FortiOS Web Networking ⚡ nuclei
N/A
UNKNOWN
EPSS
8.8%
2017 2 PoCs

A Cross-Site Scripting vulnerability in Fortinet FortiOS versions 5.6.0 and earlier allows attackers to Execute unauthorized code or commands via the action input during the activation of a FortiToken.

CVE-2015-7967
Software Genérico Networking
N/A
UNKNOWN
EPSS
0.1%
2015 1 PoC

SafeNet Authentication Service for Citrix Web Interface Agent uses a weak ACL for unspecified installation directories and executable modules, which allows local users to gain privileges by modifying an executable module.

CVE-2017-9476
Software Genérico Networking
N/A
UNKNOWN
EPSS
16.1%
2017 1 PoC

The Comcast firmware on Cisco DPC3939 (firmware version dpc3939-P20-18-v303r20421733-160420a-CMCST); Cisco DPC3939 (firmware version dpc3939-P20-18-v303r20421746-170221a-CMCST); and Arris TG1682G (eMTA&DOCSIS version 10.0.132.SIP.PC20.CT, software version TG1682_2.2p7s2_PROD_sey) devices makes it easy for remote attackers to determine the hidden SSID and passphrase for a Home Security Wi-Fi network.

CVE-2017-7398
Software Genérico Web Networking
N/A
UNKNOWN
EPSS
0.4%
2017 2 PoCs

D-Link DIR-615 HW: T1 FW:20.09 is vulnerable to Cross-Site Request Forgery (CSRF) vulnerability. This enables an attacker to perform an unwanted action on a wireless router for which the user/admin is currently authenticated, as demonstrated by changing the Security option from WPA2 to None, or changing the hiddenSSID parameter, SSID parameter, or a security-option password.

CVE-2017-7315
Software Genérico Networking
N/A
UNKNOWN
EPSS
0.9%
2017 1 PoC

An issue was discovered on Humax Digital HG100R 2.0.6 devices. To download the backup file it's not necessary to use credentials, and the router credentials are stored in plaintext inside the backup, aka GatewaySettings.bin.

CVE-2014-6598
Software Genérico Networking Database Cloud
N/A
UNKNOWN
EPSS
10.0%
2014 1 PoC

Unspecified vulnerability in the Oracle Communications Diameter Signaling Router component in Oracle Communications Applications 3.x, 4.x, and 5.0 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to Signaling - DPI.

CVE-2015-6565
Software Genérico Networking
N/A
UNKNOWN
EPSS
0.3%
2015 5 PoCs

sshd in OpenSSH 6.8 and 6.9 uses world-writable permissions for TTY devices, which allows local users to cause a denial of service (terminal disruption) or possibly have unspecified other impact by writing to a device, as demonstrated by writing an escape sequence.

CVE-2017-15654
Software Genérico Web Networking
N/A
UNKNOWN
EPSS
1.0%
2017 2 PoCs

Highly predictable session tokens in the HTTPd server in all current versions (<= 3.0.0.4.380.7743) of Asus asuswrt allow gaining administrative router access.

CVE-2017-15043
Software Genérico Web Networking Cloud
N/A
UNKNOWN
EPSS
0.0%
2017 1 PoC

A vulnerability in Sierra Wireless AirLink GX400, GX440, ES440, and LS300 routers with firmware before 4.4.5 and GX450, ES450, RV50, RV50X, MP70, and MP70E routers with firmware before 4.9 could allow an authenticated remote attacker to execute arbitrary code and gain full control of an affected system, including issuing commands with root privileges. This vulnerability is due to insufficient input validation on user-controlled input in an HTTP request to the targeted device. An attacker in possession of router login credentials could exploit this vulnerability by sending a crafted HTTP reques

CVE-2017-6411
Software Genérico Web Networking
N/A
UNKNOWN
EPSS
2.4%
2017 1 PoC

Cross Site Request Forgery (CSRF) on D-Link DSL-2730U C1 IN_1.00 devices allows remote attackers to change the DNS or firewall configuration or any password.

CVE-2015-0936
Software Genérico Networking
N/A
UNKNOWN
EPSS
86.3%
2015 2 PoCs

Ceragon FibeAir IP-10 have a default SSH public key in the authorized_keys file for the mateidu user, which allows remote attackers to obtain SSH access by leveraging knowledge of the private key.