3303 vulnerabilidades · Networking Orden: CVSS EPSS Año ID
CVE-2022-32548
Software Genérico Networking
10.0
CRITICAL
EPSS
65.6%
2022 6 PoCs

An issue was discovered on certain DrayTek Vigor routers before July 2022 such as the Vigor3910 before 4.3.1.1. /cgi-bin/wlogin.cgi has a buffer overflow via the username or password to the aa or ab field.

CVE-2022-20707
Cisco Small Business RV Series Router Firmware Networking
10.0
CRITICAL
EPSS
81.4%
2022 CWE-121 2 PoCs

Multiple vulnerabilities in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an attacker to do any of the following: Execute arbitrary code Elevate privileges Execute arbitrary commands Bypass authentication and authorization protections Fetch and run unsigned software Cause denial of service (DoS) For more information about these vulnerabilities, see the Details section of this advisory.

CVE-2022-20704
Cisco Small Business RV Series Router Firmware Networking
10.0
CRITICAL
EPSS
0.9%
2022 CWE-121 1 PoC

Multiple vulnerabilities in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an attacker to do any of the following: Execute arbitrary code Elevate privileges Execute arbitrary commands Bypass authentication and authorization protections Fetch and run unsigned software Cause denial of service (DoS) For more information about these vulnerabilities, see the Details section of this advisory.

CVE-2024-39930
Software Genérico Networking Windows
9.9
CRITICAL
EPSS
11.9%
2024 4 PoCs

The built-in SSH server of Gogs through 0.13.0 allows argument injection in internal/ssh/ssh.go, leading to remote code execution. Authenticated attackers can exploit this by opening an SSH connection and sending a malicious --split-string env request if the built-in SSH server is activated. Windows installations are unaffected.

CVE-2024-33699
WBR-6012 Networking
9.9
CRITICAL
EPSS
7.2%
2024 CWE-620 2 PoCs

The LevelOne WBR-6012 router's web application has a vulnerability in its firmware version R0.40e6, allowing attackers to change the administrator password and gain higher privileges without the current password.

CVE-2024-9463
🔥 KEV Expedition Web Networking ⚡ nuclei
9.9
CRITICAL
EPSS
94.2%
2024 CWE-78 2 PoCs

An OS command injection vulnerability in Palo Alto Networks Expedition allows an unauthenticated attacker to run arbitrary OS commands as root in Expedition, resulting in disclosure of usernames, cleartext passwords, device configurations, and device API keys of PAN-OS firewalls.

CVE-2021-42369
Software Genérico Networking Database
9.9
CRITICAL
EPSS
0.4%
2021 1 PoC

Imagicle Application Suite (for Cisco UC) before 2021.Summer.2 allows SQL injection. A low-privileged user could inject a SQL statement through the "Export to CSV" feature of the Contact Manager web GUI.

CVE-2025-20333
🔥 KEV Cisco Secure Firewall Adaptive Security Appliance (ASA) Software Web Networking
9.9
CRITICAL
EPSS
25.1%
2025 CWE-120 1 PoC

A vulnerability in the VPN web server of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an authenticated, remote attacker to execute arbitrary code on an affected device. This vulnerability is due to improper validation of user-supplied input in HTTP(S) requests. An attacker with valid VPN user credentials could exploit this vulnerability by sending crafted HTTP requests to an affected device. A successful exploit could allow the attacker to execute arbitrary code as root, possibly resulting in the complet

CVE-2025-20124
Cisco Identity Services Engine Software Web Networking
9.9
CRITICAL
EPSS
8.3%
2025 CWE-502 1 PoC

A vulnerability in an API of Cisco ISE could allow an authenticated, remote attacker to execute arbitrary commands as the root user on an affected device. This vulnerability is due to insecure deserialization of user-supplied Java byte streams by the affected software. An attacker could exploit this vulnerability by sending a crafted serialized Java object to an affected API. A successful exploit could allow the attacker to execute arbitrary commands on the device and elevate privileges. Note: To successfully exploit this vulnerability, the attacker must have valid read-only administr

CVE-2025-20156
Cisco Meeting Management Web Networking
9.9
CRITICAL
EPSS
3.4%
2025 CWE-274 1 PoC

A vulnerability in the REST API of Cisco Meeting Management could allow a remote, authenticated attacker with low privileges to elevate privileges to administrator on an affected device. This vulnerability exists because proper authorization is not enforced upon REST API users. An attacker could exploit this vulnerability by sending API requests to a specific endpoint. A successful exploit could allow the attacker to gain administrator-level control over edge nodes that are managed by Cisco Meeting Management.

CVE-2025-20286
Cisco Identity Services Engine Software Networking Database Cloud
9.9
CRITICAL
EPSS
0.2%
2025 CWE-259 1 PoC

A vulnerability in Amazon Web Services (AWS), Microsoft Azure, and Oracle Cloud Infrastructure (OCI) cloud deployments of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to access sensitive data, execute limited administrative operations, modify system configurations, or disrupt services within the impacted systems. This vulnerability exists because credentials are improperly generated when Cisco ISE is being deployed on cloud platforms, resulting in different Cisco ISE deployments sharing the same credentials. These credentials are shared across multipl

CVE-2022-26780
InRouter302 Web Networking
9.9
CRITICAL
EPSS
0.9%
2022 CWE-20 1 PoC

Multiple improper input validation vulnerabilities exists in the libnvram.so nvram_import functionality of InHand Networks InRouter302 V3.5.4. A specially-crafted file can lead to remote code execution. An attacker can send a sequence of requests to trigger this vulnerability.An improper input validation vulnerability exists in the `httpd`'s `user_define_init` function. Controlling the `user_define_timeout` nvram variable can lead to remote code execution.

CVE-2022-26510
InRouter302 Web Networking
9.9
CRITICAL
EPSS
0.5%
2022 CWE-347 1 PoC

A firmware update vulnerability exists in the iburn firmware checks functionality of InHand Networks InRouter302 V3.5.37. A specially-crafted HTTP request can lead to firmware update. An attacker can send a sequence of requests to trigger this vulnerability.

CVE-2022-26420
InRouter302 Networking
9.9
CRITICAL
EPSS
9.1%
2022 CWE-78 1 PoC

An OS command injection vulnerability exists in the console infactory_port functionality of InHand Networks InRouter302 V3.5.37. A specially-crafted series of network requests can lead to remote code execution. An attacker can send a sequence of requests to trigger this vulnerability.

CVE-2022-36786
DSL-224 Web Networking
9.9
CRITICAL
EPSS
0.4%
2022 1 PoC

DLINK - DSL-224 Post-auth RCE. DLINK router version 3.0.8 has an interface where you can configure NTP servers (Network Time Protocol) via jsonrpc API. It is possible to inject a command through this interface that will run with ROOT permissions on the router.

CVE-2022-26085
InRouter302 Web Networking
9.9
CRITICAL
EPSS
2.7%
2022 CWE-77 1 PoC

An OS command injection vulnerability exists in the httpd wlscan_ASP functionality of InHand Networks InRouter302 V3.5.4. A specially-crafted HTTP request can lead to arbitrary command execution. An attacker can make an authenticated HTTP request to trigger this vulnerability.

CVE-2022-26042
InRouter302 Networking
9.9
CRITICAL
EPSS
2.6%
2022 CWE-77 1 PoC

An OS command injection vulnerability exists in the daretools binary functionality of InHand Networks InRouter302 V3.5.4. A specially-crafted network request can lead to arbitrary command execution. An attacker can send a sequence of requests to trigger this vulnerability.

CVE-2022-26781
InRouter302 Web Networking
9.9
CRITICAL
EPSS
0.9%
2022 CWE-20 1 PoC

Multiple improper input validation vulnerabilities exists in the libnvram.so nvram_import functionality of InHand Networks InRouter302 V3.5.4. A specially-crafted file can lead to remote code execution. An attacker can send a sequence of requests to trigger this vulnerability.An improper input validation vulnerability exists in the `httpd`'s `user_define_print` function. Controlling the `user_define_timeout` nvram variable can lead to remote code execution.

CVE-2022-21809
InRouter302 Web Networking
9.9
CRITICAL
EPSS
1.4%
2022 CWE-377 1 PoC

A file write vulnerability exists in the httpd upload.cgi functionality of InHand Networks InRouter302 V3.5.4. A specially-crafted HTTP request can lead to arbitrary file upload. An attacker can upload a malicious file to trigger this vulnerability.

CVE-2022-26075
InRouter302 Networking
9.9
CRITICAL
EPSS
9.1%
2022 CWE-78 1 PoC

An OS command injection vulnerability exists in the console infactory_wlan functionality of InHand Networks InRouter302 V3.5.37. A specially-crafted series of network requests can lead to remote code execution. An attacker can send a sequence of requests to trigger this vulnerability.