265 vulnerabilidades · Networking Orden: CVSS EPSS Año ID
CVE-2022-27268
Software Genérico Networking
N/A
UNKNOWN
EPSS
0.8%
2022 1 PoC

InHand Networks InRouter 900 Industrial 4G Router before v1.0.0.r11700 was discovered to contain a remote code execution (RCE) vulnerability via the component get_cgi_from_memory. This vulnerability is triggered via a crafted packet.

CVE-2022-27274
Software Genérico Networking
N/A
UNKNOWN
EPSS
1.3%
2022 1 PoC

InHand Networks InRouter 900 Industrial 4G Router before v1.0.0.r11700 was discovered to contain a remote code execution (RCE) vulnerability via the function sub_12028. This vulnerability is triggered via a crafted packet.

CVE-2022-0953
Anti-Malware Security and Brute-Force Firewall Web Networking Windows
N/A
UNKNOWN
EPSS
0.3%
2022 CWE-79 1 PoC

The Anti-Malware Security and Brute-Force Firewall WordPress plugin before 4.20.96 does not sanitise and escape the QUERY_STRING before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting in browsers which do not encode characters

CVE-2022-27275
Software Genérico Networking
N/A
UNKNOWN
EPSS
1.3%
2022 1 PoC

InHand Networks InRouter 900 Industrial 4G Router before v1.0.0.r11700 was discovered to contain a remote code execution (RCE) vulnerability via the function sub_122D0. This vulnerability is triggered via a crafted packet.

CVE-2022-24693
Software Genérico Networking
N/A
UNKNOWN
EPSS
2.3%
2022 1 PoC

Baicells Nova436Q and Neutrino 430 devices with firmware through QRTB 2.7.8 have hardcoded credentials that are easily discovered, and can be used by remote attackers to authenticate via ssh. (The credentials are stored in the firmware, encrypted by the crypt function.)

CVE-2022-30270
Software Genérico Networking
N/A
UNKNOWN
EPSS
0.3%
2022 1 PoC

The Motorola ACE1000 RTU through 2022-05-02 has default credentials. It exposes an SSH interface on port 22/TCP. This interface is used for remote maintenance and for SFTP file-transfer operations that are part of engineering software functionality. Access to this interface is controlled by 5 preconfigured accounts (root, abuilder, acelogin, cappl, ace), all of which come with default credentials. Although the ACE1000 documentation mentions the root, abuilder and acelogin accounts and instructs users to change the default credentials, the cappl and ace accounts remain undocumented and thus are

CVE-2022-35192
Software Genérico Networking
N/A
UNKNOWN
EPSS
0.8%
2022 1 PoC

D-Link Wireless AC1200 Dual Band VDSL ADSL Modem Router DSL-3782 Firmware v1.01 allows unauthenticated attackers to cause a Denial of Service (DoS) via the User parameter or Pwd parameter to Login.asp.

CVE-2022-26987
Software Genérico Networking
N/A
UNKNOWN
EPSS
0.5%
2022 1 PoC

TP-Link TL-WDR7660 2.0.30, Mercury D196G 20200109_2.0.4, and Fast FAC1900R 20190827_2.0.2 routers have a stack overflow issue in `MmtAtePrase` function. Local users could get remote code execution.

CVE-2022-29383
Software Genérico Networking Database Cloud ⚡ nuclei
N/A
UNKNOWN
EPSS
75.2%
2022 3 PoCs

NETGEAR ProSafe SSL VPN firmware FVS336Gv2 and FVS336Gv3 was discovered to contain a SQL injection vulnerability via USERDBDomains.Domainname at cgi-bin/platform.cgi.

CVE-2022-26634
Software Genérico Networking
N/A
UNKNOWN
EPSS
0.2%
2022 1 PoC

HMA VPN v5.3.5913.0 contains an unquoted service path which allows attackers to escalate privileges to the system level.

CVE-2022-29620
Software Genérico Networking
N/A
UNKNOWN
EPSS
1.4%
2022 3 PoCs

FileZilla v3.59.0 allows attackers to obtain cleartext passwords of connected SSH or FTP servers via a memory dump.- NOTE: the vendor does not consider this a vulnerability

CVE-2022-22899
Software Genérico Networking
N/A
UNKNOWN
EPSS
0.2%
2022 1 PoC

Core FTP / SFTP Server v2 Build 725 was discovered to allow unauthenticated attackers to cause a Denial of Service (DoS) via a crafted packet through the SSH service.

CVE-2022-45552
Software Genérico Networking
N/A
UNKNOWN
EPSS
0.3%
2022 1 PoC

An Insecure Permissions vulnerability in Shenzhen Zhiboton Electronics ZBT WE1626 Router v 21.06.18 allows attackers to obtain sensitive information via SPI bus interface connected to pinout of the NAND flash memory.

CVE-2022-25389
Software Genérico Web Networking
N/A
UNKNOWN
EPSS
0.3%
2022 1 PoC

DCN Firewall DCME-520 was discovered to contain an arbitrary file download vulnerability via the path parameter in the file /audit/log/log_management.php.

CVE-2022-38368
Software Genérico Web Networking
N/A
UNKNOWN
EPSS
0.4%
2022 1 PoC

An issue was discovered in Aviatrix Gateway before 6.6.5712 and 6.7.x before 6.7.1376. Because Gateway API functions mishandle authentication, an authenticated VPN user can inject arbitrary commands.

CVE-2022-31845
Software Genérico Networking ⚡ nuclei
N/A
UNKNOWN
EPSS
53.1%
2022 0 PoCs

A vulnerability in live_check.shtml of WAVLINK WN535 G3 M35G3R.V5030.180927 allows attackers to obtain sensitive router information via execution of the exec cmd function.

CVE-2022-30521
Software Genérico Web Networking
N/A
UNKNOWN
EPSS
1.8%
2022 1 PoC

The LAN-side Web-Configuration Interface has Stack-based Buffer Overflow vulnerability in the D-Link Wi-Fi router firmware DIR-890L DIR890LA1_FW107b09.bin and previous versions. The function created at 0x17958 of /htdocs/cgibin will call sprintf without checking the length of strings in parameters given by HTTP header and can be controlled by users easily. The attackers can exploit the vulnerability to carry out arbitrary code by means of sending a specially constructed payload to port 49152.

CVE-2022-31876
Software Genérico Web Networking
N/A
UNKNOWN
EPSS
0.5%
2022 1 PoC

netgear wnap320 router WNAP320_V2.0.3_firmware is vulnerable to Incorrect Access Control via /recreate.php, which can leak all users cookies.

CVE-2022-22274
SonicOS Web Networking
N/A
UNKNOWN
EPSS
47.0%
2022 CWE-121 4 PoCs

A Stack-based buffer overflow vulnerability in the SonicOS via HTTP request allows a remote unauthenticated attacker to cause Denial of Service (DoS) or potentially results in code execution in the firewall.

CVE-2022-36234
Software Genérico Networking
N/A
UNKNOWN
EPSS
0.1%
2022 1 PoC

SimpleNetwork TCP Server commit 29bc615f0d9910eb2f59aa8dff1f54f0e3af4496 was discovered to contain a double free vulnerability which is exploited via crafted TCP packets.