321 vulnerabilidades · Networking Orden: CVSS EPSS Año ID
CVE-2020-15315
Software Genérico Networking Cloud
N/A
UNKNOWN
EPSS
0.3%
2020 1 PoC

Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has a hardcoded DSA SSH key for the root account within the /opt/axess chroot directory tree.

CVE-2020-25757
Software Genérico Web Networking
N/A
UNKNOWN
EPSS
0.5%
2020 1 PoC

A lack of input validation and access controls in Lua CGIs on D-Link DSR VPN routers may result in arbitrary input being passed to system command APIs, resulting in arbitrary command execution with root privileges. This affects DSR-150, DSR-250, DSR-500, and DSR-1000AC with firmware 3.14 and 3.17.

CVE-2020-15499
Software Genérico Web Networking
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

An issue was discovered on ASUS RT-AC1900P routers before 3.0.0.4.385_20253. They allow XSS via spoofed Release Notes on the Firmware Upgrade page.

CVE-2020-11966
Software Genérico Networking
N/A
UNKNOWN
EPSS
0.8%
2020 1 PoC

In IQrouter through 3.3.1, the Lua function reset_password in the web-panel allows remote attackers to change the root password arbitrarily. Note: The vendor claims that this vulnerability can only occur on a brand-new network that, after initiating the forced initial configuration (which has a required step for setting a secure password on the system), makes this CVE invalid. This vulnerability is “true for any unconfigured release of OpenWRT, and true of many other new Linux distros prior to being configured for the first time”

CVE-2020-15078
OpenVPN Networking
N/A
UNKNOWN
EPSS
0.3%
2020 CWE-305 2 PoCs

OpenVPN 2.5.1 and earlier versions allows a remote attackers to bypass authentication and access control channel data on servers configured with deferred authentication, which can be used to potentially trigger further information leaks.

CVE-2020-5797
TP-Link Archer C9 A1 Networking
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

UNIX Symbolic Link (Symlink) Following in TP-Link Archer C9(US)_V1_180125 firmware allows an unauthenticated actor, with physical access and network access, to read sensitive files and write to a limited set of files after plugging a crafted USB drive into the router.

CVE-2020-13118
Software Genérico Web Networking Database
N/A
UNKNOWN
EPSS
3.7%
2020 1 PoC

An issue was discovered in Mikrotik-Router-Monitoring-System through 2018-10-22. SQL Injection exists in check_community.php via the parameter community.

CVE-2020-11622
Software Genérico Networking Cloud
N/A
UNKNOWN
EPSS
0.3%
2020 1 PoC

A vulnerability exists in Arista’s Cloud EOS VM / vEOS 4.23.2M and below releases in the 4.23.x train, 4.22.4M and below releases in the 4.22.x train, 4.21.3M to 4.21.9M releases in the 4.21.x train, 4.21.3FX-7368.*, 4.21.4-FCRFX.*, 4.21.4.1, 4.21.7.1, 4.22.2.0.1, 4.22.2.2.1, 4.22.3.1, and 4.23.2.1 Router code in a scenario where TCP MSS options are configured.

CVE-2020-17494
Software Genérico Networking
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

Untangle Firewall NG before 16.0 uses MD5 for passwords.

CVE-2020-16137
Software Genérico Networking
N/A
UNKNOWN
EPSS
73.2%
2020 1 PoC

A privilege escalation issue in Cisco Unified IP Conference Station 7937G 1-4-4-0 through 1-4-5-7 allows attackers to reset the credentials for the SSH administrative console to arbitrary values. Note: We cannot prove this vulnerability exists. Out of an abundance of caution, this CVE is being assigned to better serve our customers and ensure all who are still running this product understand that the product is end of life and should be removed or upgraded. For more information on this, and how to upgrade, refer to the CVE’s reference information

CVE-2020-13620
Software Genérico Web Networking
N/A
UNKNOWN
EPSS
0.1%
2020 2 PoCs

Fastweb FASTGate GPON FGA2130FWB devices through 2020-05-26 allow CSRF via the router administration web panel, leading to an attacker's ability to perform administrative actions such as modifying the configuration.

CVE-2020-8217
Pulse Connect Secure Web Networking
N/A
UNKNOWN
EPSS
0.1%
2020 CWE-79 1 PoC

A cross site scripting (XSS) vulnerability in Pulse Connect Secure <9.1R8 allowed attackers to exploit in the URL used for Citrix ICA.

CVE-2020-9292
Fortinet FortiSIEMWindowsAgent Networking Windows
N/A
UNKNOWN
EPSS
0.5%
2020 1 PoC

An unquoted service path vulnerability in the FortiSIEM Windows Agent component may allow an attacker to gain elevated privileges via the AoWinAgt executable service path.

CVE-2020-20215
Software Genérico Networking
N/A
UNKNOWN
EPSS
0.9%
2020 1 PoC

Mikrotik RouterOs 6.44.6 (long-term tree) suffers from a memory corruption vulnerability in the /nova/bin/diskd process. An authenticated remote attacker can cause a Denial of Service due to invalid memory access.

CVE-2020-20221
Software Genérico Networking
N/A
UNKNOWN
EPSS
1.1%
2020 2 PoCs

Mikrotik RouterOs before 6.44.6 (long-term tree) suffers from an uncontrolled resource consumption vulnerability in the /nova/bin/cerm process. An authenticated remote attacker can cause a Denial of Service due to overloading the systems CPU.

CVE-2020-21935
Software Genérico Networking
N/A
UNKNOWN
EPSS
3.3%
2020 1 PoC

A command injection vulnerability in HNAP1/GetNetworkTomographySettings of Motorola CX2 router CX 1.0.2 Build 20190508 Rel.97360n allows attackers to execute arbitrary code.

CVE-2020-19323
Software Genérico Networking
N/A
UNKNOWN
EPSS
0.3%
2020 1 PoC

An issue was discovered in /bin/mini_upnpd on D-Link DIR-619L 2.06beta devices. There is a heap buffer overflow allowing remote attackers to restart router via the M-search request ST parameter. No authentication required

CVE-2020-16139
Software Genérico Networking ⚡ nuclei
N/A
UNKNOWN
EPSS
87.6%
2020 1 PoC

A denial-of-service in Cisco Unified IP Conference Station 7937G 1-4-4-0 through 1-4-5-7 allows attackers restart the device remotely through sending specially crafted packets. Note: We cannot prove this vulnerability exists. Out of an abundance of caution, this CVE is being assigned to better serve our customers and ensure all who are still running this product understand that the product is end of life and should be removed or upgraded. For more information on this, and how to upgrade, refer to the CVE’s reference information

CVE-2020-15317
Software Genérico Networking Cloud
N/A
UNKNOWN
EPSS
0.3%
2020 1 PoC

Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has a hardcoded RSA SSH key for the root account within the /opt/axess chroot directory tree.

CVE-2020-20220
Software Genérico Networking
N/A
UNKNOWN
EPSS
1.0%
2020 2 PoCs

Mikrotik RouterOs prior to stable 6.47 suffers from a memory corruption vulnerability in the /nova/bin/bfd process. An authenticated remote attacker can cause a Denial of Service (NULL pointer dereference).