214 vulnerabilidades · Networking Orden: CVSS EPSS Año ID
CVE-2021-28130
Software Genérico Networking Windows
N/A
UNKNOWN
EPSS
0.1%
2021 1 PoC

Dr.Web Firewall 12.5.2.4160 on Windows incorrectly restricts applications signed by Dr.Web. A DLL for a custom payload within a legitimate binary (e.g., frwl_svc.exe) bypasses firewall filters.

CVE-2021-46315
Software Genérico Web Networking
N/A
UNKNOWN
EPSS
32.0%
2021 1 PoC

Remote Command Execution (RCE) vulnerability exists in HNAP1/control/SetWizardConfig.php in D-Link Router DIR-846 DIR846A1_FW100A43.bin and DIR846enFW100A53DLA-Retail.bin. Malicoius users can use this vulnerability to use "\ " or backticks in the shell metacharacters in the ssid0 or ssid1 parameters to cause arbitrary command execution. Since CVE-2019-17510 vulnerability has not been patched and improved www/hnap1/control/setwizardconfig.php, can also use line breaks and backquotes to bypass.

CVE-2021-39615
Software Genérico Networking
N/A
UNKNOWN
EPSS
2.3%
2021 2 PoCs

D-Link DSR-500N version 1.02 contains hard-coded credentials for undocumented user accounts in the '/etc/passwd' file.If an attacker succeeds in recovering the cleartext password of the identified hash value, he will be able to log in via SSH or Telnet and thus gain access to the underlying embedded Linux operating system on the device. Fixed in version 2.12/2. NOTE: This vulnerability only affects products that are no longer supported by the maintainer

CVE-2021-20140
Gryphon Tower router Networking
N/A
UNKNOWN
EPSS
7.8%
2021 1 PoC

An unauthenticated command injection vulnerability exists in the parameters of operation 10 in the controller_server service on Gryphon Tower routers. An unauthenticated remote attacker on the same network can execute commands as root on the device by sending a specially crafted malicious packet to the controller_server service on port 9999.

CVE-2021-43164
Software Genérico Web Networking
N/A
UNKNOWN
EPSS
26.3%
2021 2 PoCs

A Remote Code Execution (RCE) vulnerability exists in Ruijie Networks Ruijie RG-EW Series Routers up to ReyeeOS 1.55.1915 / EW_3.0(1)B11P55 via the updateVersion function in /cgi-bin/luci/api/wireless.

CVE-2021-43729
Software Genérico Web Networking
N/A
UNKNOWN
EPSS
0.4%
2021 1 PoC

Pix-Link MiNi Router 28K.MiniRouter.20190211 was discovered to contain a stored cross-site scripting (XSS) vulnerability due to an unsanitized Security Key parameter.

CVE-2021-28041
Software Genérico Networking
N/A
UNKNOWN
EPSS
0.2%
2021 1 PoC

ssh-agent in OpenSSH before 8.5 has a double free that may be relevant in a few less-common scenarios, such as unconstrained agent-socket access on a legacy operating system, or the forwarding of an agent to an attacker-controlled host.

CVE-2021-27691
Software Genérico Networking
N/A
UNKNOWN
EPSS
4.4%
2021 2 PoCs

Command Injection in Tenda G0 routers with firmware versions v15.11.0.6(9039)_CN and v15.11.0.5(5876)_CN , and Tenda G1 and G3 routers with firmware versions v15.11.0.17(9502)_CN or v15.11.0.16(9024)_CN allows remote attackers to execute arbitrary OS commands via a crafted action/setDebugCfg request. This occurs because the "formSetDebugCfg" function executes glibc's system function with untrusted input.

CVE-2021-40847
Software Genérico Web Networking
N/A
UNKNOWN
EPSS
5.4%
2021 2 PoCs

The update process of the Circle Parental Control Service on various NETGEAR routers allows remote attackers to achieve remote code execution as root via a MitM attack. While the parental controls themselves are not enabled by default on the routers, the Circle update daemon, circled, is enabled by default. This daemon connects to Circle and NETGEAR to obtain version information and updates to the circled daemon and its filtering database. However, database updates from NETGEAR are unsigned and downloaded via cleartext HTTP. As such, an attacker with the ability to perform a MitM attack on the

CVE-2021-20031
SonicOS Networking ⚡ nuclei
N/A
UNKNOWN
EPSS
36.2%
2021 CWE-601 1 PoC

A Host Header Redirection vulnerability in SonicOS potentially allows a remote attacker to redirect firewall management users to arbitrary web domains.

CVE-2021-33962
Software Genérico Web Networking
N/A
UNKNOWN
EPSS
3.8%
2021 1 PoC

China Mobile An Lianbao WF-1 router v1.0.1 is affected by an OS command injection vulnerability in the web interface /api/ZRUsb/pop_usb_device component.

CVE-2021-24956
Blog2Social: Social Media Auto Post & Scheduler Web Networking Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
1.5%
2021 CWE-79 1 PoC

The Blog2Social: Social Media Auto Post & Scheduler WordPress plugin before 6.8.7 does not sanitise and escape the b2sShowByDate parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting issue

CVE-2021-33963
Software Genérico Web Networking
N/A
UNKNOWN
EPSS
4.0%
2021 1 PoC

China Mobile An Lianbao WF-1 v1.0.1 router web interface through /api/ZRMacClone/mac_addr_clone receives parameters by POST request, and the parameter macType has a command injection vulnerability. An attacker can use the vulnerability to execute remote commands.

CVE-2021-31152
Software Genérico Web Networking
N/A
UNKNOWN
EPSS
1.4%
2021 2 PoCs

Multilaser Router AC1200 V02.03.01.45_pt contains a cross-site request forgery (CSRF) vulnerability. An attacker can enable remote access, change passwords, and perform other actions through misconfigured requests, entries, and headers.