265 vulnerabilidades · Networking Orden: CVSS EPSS Año ID
CVE-2022-37661
Software Genérico Networking
N/A
UNKNOWN
EPSS
30.7%
2022 3 PoCs

SmartRG SR506n 2.5.15 and SR510n 2.6.13 routers are vulnerable to Remote Code Execution (RCE) via the ping host feature.

CVE-2022-30327
Software Genérico Web Networking
N/A
UNKNOWN
EPSS
0.1%
2022 2 PoCs

An issue was found on TRENDnet TEW-831DR 1.0 601.130.1.1356 devices. The web interface is vulnerable to CSRF. An attacker can change the pre-shared key of the Wi-Fi router if the interface's IP address is known.

CVE-2022-23900
Software Genérico Web Networking
N/A
UNKNOWN
EPSS
5.8%
2022 1 PoC

A command injection vulnerability in the API of the Wavlink WL-WN531P3 router, version M31G3.V5030.201204, allows an attacker to achieve unauthorized remote code execution via a malicious POST request through /cgi-bin/adm.cgi.

CVE-2022-1386
Fusion Builder Web Networking Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
93.6%
2022 CWE-918 9 PoCs

The Fusion Builder WordPress plugin before 3.6.2, used in the Avada theme, does not validate a parameter in its forms which could be used to initiate arbitrary HTTP requests. The data returned is then reflected back in the application's response. This could be used to interact with hosts on the server's local network bypassing firewalls and access control measures.

CVE-2022-26565
Software Genérico Web Networking
N/A
UNKNOWN
EPSS
0.3%
2022 1 PoC

A cross-site scripting (XSS) vulnerability in Totaljs all versions before commit 95f54a5commit, allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Page Name text field when creating a new page.

CVE-2022-30272
Software Genérico Networking
N/A
UNKNOWN
EPSS
0.1%
2022 1 PoC

The Motorola ACE1000 RTU through 2022-05-02 mishandles firmware integrity. It utilizes either the STS software suite or ACE1000 Easy Configurator for performing firmware updates. In case of the Easy Configurator, firmware updates are performed through access to the Web UI where file system, kernel, package, bundle, or application images can be installed. Firmware updates for the Front End Processor (FEP) module are performed via access to the SSH interface (22/TCP), where a .hex file image is transferred and a bootloader script invoked. File system, kernel, package, and bundle updates are supp

CVE-2022-2599
Anti-Malware Security and Brute-Force Firewall Web Networking Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
30.9%
2022 CWE-79 1 PoC

The Anti-Malware Security and Brute-Force Firewall WordPress plugin before 4.21.83 does not sanitise and escape some parameters before outputting them back in an admin dashboard, leading to Reflected Cross-Site Scripting

CVE-2022-37232
Software Genérico Web Networking
N/A
UNKNOWN
EPSS
0.9%
2022 1 PoC

Netgear N300 wireless router wnr2000v4-V1.0.0.70 is vulnerable to Buffer Overflow via uhttpd. There is a stack overflow vulnerability caused by strcpy.

CVE-2022-34960
Software Genérico DevOps Networking
N/A
UNKNOWN
EPSS
0.5%
2022 2 PoCs

The container package in MikroTik RouterOS 7.4beta4 allows an attacker to create mount points pointing to symbolic links, which resolve to locations on the host device. This allows the attacker to mount any arbitrary file to any location on the host.

CVE-2022-25166
Software Genérico Networking Cloud Windows
N/A
UNKNOWN
EPSS
1.1%
2022 1 PoC

An issue was discovered in Amazon AWS VPN Client 2.0.0. It is possible to include a UNC path in the OpenVPN configuration file when referencing file paths for parameters (such as auth-user-pass). When this file is imported and the client attempts to validate the file path, it performs an open operation on the path and leaks the user's Net-NTLMv2 hash to an external server. This could be exploited by having a user open a crafted malicious ovpn configuration file.

CVE-2022-0211
Shield Security – Scanners, Security Hardening, Brute Force Protection & Firewall Web Networking Windows
N/A
UNKNOWN
EPSS
0.2%
2022 CWE-79 1 PoC

The Shield Security WordPress plugin before 13.0.6 does not sanitise and escape admin notes, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html is disallowed.

CVE-2022-36633
Software Genérico Networking
N/A
UNKNOWN
EPSS
30.3%
2022 2 PoCs

Teleport 9.3.6 is vulnerable to Command injection leading to Remote Code Execution. An attacker can craft a malicious ssh agent installation link by URL encoding a bash escape with carriage return line feed. This url encoded payload can be used in place of a token and sent to a user in a social engineering attack. This is fully unauthenticated attack utilizing the trusted teleport server to deliver the payload.

CVE-2022-39849
Samsung Mobile Devices Networking
N/A
UNKNOWN
EPSS
0.0%
2022 CWE-284 1 PoC

Improper access control in knox_vpn_policy service prior to SMR Oct-2022 Release 1 allows allows unauthorized read of configuration data.

CVE-2022-29013
Software Genérico Web Networking ⚡ nuclei
N/A
UNKNOWN
EPSS
92.6%
2022 2 PoCs

A command injection in the command parameter of Razer Sila Gaming Router v2.0.441_api-2.0.418 allows attackers to execute arbitrary commands via a crafted POST request.

CVE-2022-2663
Linux kernel Networking
N/A
UNKNOWN
EPSS
0.2%
2022 CWE-923 1 PoC

An issue was found in the Linux kernel in nf_conntrack_irc where the message handling can be confused and incorrectly matches the message. A firewall may be able to be bypassed when users are using unencrypted IRC with nf_conntrack_irc configured.

CVE-2022-26186
Software Genérico Networking
N/A
UNKNOWN
EPSS
23.8%
2022 1 PoC

TOTOLINK N600R V4.3.0cu.7570_B20200620 was discovered to contain a command injection vulnerability via the exportOvpn interface at cstecgi.cgi.

CVE-2022-32985
Software Genérico Networking
N/A
UNKNOWN
EPSS
0.6%
2022 1 PoC

libnx_apl.so on Nexans FTTO GigaSwitch before 6.02N and 7.x before 7.02 implements a Backdoor Account for SSH logins on port 50200 or 50201.

CVE-2022-27271
Software Genérico Networking
N/A
UNKNOWN
EPSS
1.3%
2022 1 PoC

InHand Networks InRouter 900 Industrial 4G Router before v1.0.0.r11700 was discovered to contain a remote code execution (RCE) vulnerability via the component python-lib. This vulnerability is triggered via a crafted packet.

CVE-2022-31847
Software Genérico Networking ⚡ nuclei
N/A
UNKNOWN
EPSS
50.6%
2022 0 PoCs

A vulnerability in /cgi-bin/ExportAllSettings.sh of WAVLINK WN579 X3 M79X3.V5030.180719 allows attackers to obtain sensitive router information via a crafted POST request.

CVE-2022-30325
Software Genérico Networking
N/A
UNKNOWN
EPSS
0.1%
2022 2 PoCs

An issue was found on TRENDnet TEW-831DR 1.0 601.130.1.1356 devices. The default pre-shared key for the Wi-Fi networks is the same for every router except for the last four digits. The device default pre-shared key for both 2.4 GHz and 5 GHz networks can be guessed or brute-forced by an attacker within range of the Wi-Fi network.