3303 vulnerabilidades · Networking Orden: CVSS EPSS Año ID
CVE-2017-7398
Software Genérico Web Networking
N/A
UNKNOWN
EPSS
0.4%
2017 2 PoCs

D-Link DIR-615 HW: T1 FW:20.09 is vulnerable to Cross-Site Request Forgery (CSRF) vulnerability. This enables an attacker to perform an unwanted action on a wireless router for which the user/admin is currently authenticated, as demonstrated by changing the Security option from WPA2 to None, or changing the hiddenSSID parameter, SSID parameter, or a security-option password.

CVE-2017-7315
Software Genérico Networking
N/A
UNKNOWN
EPSS
0.9%
2017 1 PoC

An issue was discovered on Humax Digital HG100R 2.0.6 devices. To download the backup file it's not necessary to use credentials, and the router credentials are stored in plaintext inside the backup, aka GatewaySettings.bin.

CVE-2019-18810
Software Genérico Networking
N/A
UNKNOWN
EPSS
1.3%
2019 2 PoCs

A memory leak in the komeda_wb_connector_add() function in drivers/gpu/drm/arm/display/komeda/komeda_wb_connector.c in the Linux kernel before 5.3.8 allows attackers to cause a denial of service (memory consumption) by triggering drm_writeback_connector_init() failures, aka CID-a0ecd6fdbf5d.

CVE-2020-28137
Software Genérico Web Networking
N/A
UNKNOWN
EPSS
0.1%
2020 1 PoC

Cross site request forgery (CSRF) in Genexis Platinum 4410 V2-1.28, allows attackers to cause a denial of service by continuously restarting the router.

CVE-2014-6598
Software Genérico Networking Database Cloud
N/A
UNKNOWN
EPSS
10.0%
2014 1 PoC

Unspecified vulnerability in the Oracle Communications Diameter Signaling Router component in Oracle Communications Applications 3.x, 4.x, and 5.0 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to Signaling - DPI.

CVE-2015-6565
Software Genérico Networking
N/A
UNKNOWN
EPSS
0.3%
2015 5 PoCs

sshd in OpenSSH 6.8 and 6.9 uses world-writable permissions for TTY devices, which allows local users to cause a denial of service (terminal disruption) or possibly have unspecified other impact by writing to a device, as demonstrated by writing an escape sequence.

CVE-2017-15654
Software Genérico Web Networking
N/A
UNKNOWN
EPSS
1.0%
2017 2 PoCs

Highly predictable session tokens in the HTTPd server in all current versions (<= 3.0.0.4.380.7743) of Asus asuswrt allow gaining administrative router access.

CVE-2017-15043
Software Genérico Web Networking Cloud
N/A
UNKNOWN
EPSS
0.0%
2017 1 PoC

A vulnerability in Sierra Wireless AirLink GX400, GX440, ES440, and LS300 routers with firmware before 4.4.5 and GX450, ES450, RV50, RV50X, MP70, and MP70E routers with firmware before 4.9 could allow an authenticated remote attacker to execute arbitrary code and gain full control of an affected system, including issuing commands with root privileges. This vulnerability is due to insufficient input validation on user-controlled input in an HTTP request to the targeted device. An attacker in possession of router login credentials could exploit this vulnerability by sending a crafted HTTP reques

CVE-2017-6411
Software Genérico Web Networking
N/A
UNKNOWN
EPSS
2.4%
2017 1 PoC

Cross Site Request Forgery (CSRF) on D-Link DSL-2730U C1 IN_1.00 devices allows remote attackers to change the DNS or firewall configuration or any password.

CVE-2015-0936
Software Genérico Networking
N/A
UNKNOWN
EPSS
86.3%
2015 2 PoCs

Ceragon FibeAir IP-10 have a default SSH public key in the authorized_keys file for the mateidu user, which allows remote attackers to obtain SSH access by leveraging knowledge of the private key.

CVE-2017-14190
FortiOS Web Networking
N/A
UNKNOWN
EPSS
0.4%
2017 1 PoC

A Cross-site Scripting vulnerability in Fortinet FortiOS 5.6.0 to 5.6.2, 5.4.0 to 5.4.7, 5.2 and earlier, allows attacker to inject arbitrary web script or HTML via maliciously crafted "Host" header in user HTTP requests.

CVE-2017-7521
OpenVPN Networking
N/A
UNKNOWN
EPSS
0.5%
2017 CWE-400 1 PoC

OpenVPN versions before 2.4.3 and before 2.3.17 are vulnerable to remote denial-of-service due to memory exhaustion caused by memory leaks and double-free issue in extract_x509_extension().

CVE-2017-18374
Software Genérico Networking
N/A
UNKNOWN
EPSS
5.2%
2017 3 PoCs

The ZyXEL P660HN-T1A v1 TCLinux Fw $7.3.15.0 v001 / 3.40(ULM.0)b31 router distributed by TrueOnline has two user accounts with default passwords, including a hardcoded service account with the username true and password true. These accounts can be used to login to the web interface, exploit authenticated command injections and change router settings for malicious purposes.

CVE-2007-4415
Software Genérico Networking Windows
N/A
UNKNOWN
EPSS
0.0%
2007 1 PoC

Cisco VPN Client on Windows before 5.0.01.0600, and the 5.0.01.0600 InstallShield (IS) release, uses weak permissions for cvpnd.exe (Modify granted to Interactive Users), which allows local users to gain privileges via a modified cvpnd.exe.

CVE-2007-2242
Software Genérico Networking
N/A
UNKNOWN
EPSS
33.4%
2007 2 PoCs

The IPv6 protocol allows remote attackers to cause a denial of service via crafted IPv6 type 0 route headers (IPV6_RTHDR_TYPE_0) that create network amplification between two routers.

CVE-2007-1068
Software Genérico Networking
N/A
UNKNOWN
EPSS
0.1%
2007 1 PoC

The (1) TTLS CHAP, (2) TTLS MSCHAP, (3) TTLS MSCHAPv2, (4) TTLS PAP, (5) MD5, (6) GTC, (7) LEAP, (8) PEAP MSCHAPv2, (9) PEAP GTC, and (10) FAST authentication methods in Cisco Secure Services Client (CSSC) 4.x, Trust Agent 1.x and 2.x, Cisco Security Agent (CSA) 5.0 and 5.1 (when a vulnerable Trust Agent has been deployed), and the Meetinghouse AEGIS SecureConnect Client store transmitted authentication credentials in plaintext log files, which allows local users to obtain sensitive information by reading these files, aka CSCsg34423.

CVE-2007-4430
Software Genérico Networking
N/A
UNKNOWN
EPSS
27.0%
2007 1 PoC

Unspecified vulnerability in Cisco IOS 12.0 through 12.4 allows context-dependent attackers to cause a denial of service (device restart and BGP routing table rebuild) via certain regular expressions in a "show ip bgp regexp" command. NOTE: unauthenticated remote attacks are possible in environments with anonymous telnet and Looking Glass access.

CVE-2014-4728
Software Genérico Networking
N/A
UNKNOWN
EPSS
1.2%
2014 2 PoCs

The web server in the TP-LINK N750 Wireless Dual Band Gigabit Router (TL-WDR4300) with firmware before 140916 allows remote attackers to cause a denial of service (crash) via a long header in a GET request.

CVE-2015-1570
Software Genérico Networking
N/A
UNKNOWN
EPSS
0.1%
2015 1 PoC

The Endpoint Control protocol implementation in Fortinet FortiClient 5.2.3.091 for Android and 5.2.028 for iOS does not validate certificates, which makes it easier for man-in-the-middle attackers to spoof servers via a crafted certificate.

CVE-2017-11361
Software Genérico Networking
N/A
UNKNOWN
EPSS
0.6%
2017 1 PoC

Inteno routers have a JUCI ACL misconfiguration that allows the "user" account to read files, write to files, and add root SSH keys via JSON commands to ubus. (Exploitation is sometimes easy because the "user" password might be "user" or might match the Wi-Fi key.)