265 vulnerabilidades · Networking Orden: CVSS EPSS Año ID
CVE-2022-42058
Software Genérico Networking
9.8
CRITICAL
EPSS
1.1%
2022 2 PoCs

Tenda AC1200 Router Model W15Ev2 V15.11.0.10(1576) was discovered to contain a stack overflow via the setRemoteWebManage function. This vulnerability allows attackers to cause a Denial of Service (DoS) via crafted overflow data.

CVE-2022-44197
Software Genérico Networking
9.8
CRITICAL
EPSS
0.5%
2022 1 PoC

Netgear R7000P V1.3.0.8 is vulnerable to Buffer Overflow via parameter openvpn_server_ip.

CVE-2022-24706
🔥 KEV Apache CouchDB Web Networking
9.8
CRITICAL
EPSS
94.4%
2022 CWE-1188 9 PoCs

In Apache CouchDB prior to 3.2.2, an attacker can access an improperly secured default installation without authenticating and gain admin privileges. The CouchDB documentation has always made recommendations for properly securing an installation, including recommending using a firewall in front of all CouchDB installations.

CVE-2022-28321
Software Genérico Networking
9.8
CRITICAL
EPSS
0.2%
2022 1 PoC

The Linux-PAM package before 1.5.2-6.1 for openSUSE Tumbleweed allows authentication bypass for SSH logins. The pam_access.so module doesn't correctly restrict login if a user tries to connect from an IP address that is not resolvable via DNS. In such conditions, a user with denied access to a machine can still get access. NOTE: the relevance of this issue is largely limited to openSUSE Tumbleweed and openSUSE Factory; it does not affect Linux-PAM upstream.

CVE-2022-44196
Software Genérico Networking
9.8
CRITICAL
EPSS
0.5%
2022 1 PoC

Netgear R7000P V1.3.0.8 is vulnerable to Buffer Overflow via parameter openvpn_push1.

CVE-2022-40684
🔥 KEV Fortinet FortiOS, FortiProxy, FortiSwitchManager Web Networking ⚡ nuclei
9.8
CRITICAL
EPSS
94.4%
2022 27 PoCs

An authentication bypass using an alternate path or channel [CWE-288] in Fortinet FortiOS version 7.2.0 through 7.2.1 and 7.0.0 through 7.0.6, FortiProxy version 7.2.0 and version 7.0.0 through 7.0.6 and FortiSwitchManager version 7.2.0 and 7.0.0 allows an unauthenticated atttacker to perform operations on the administrative interface via specially crafted HTTP or HTTPS requests.

CVE-2022-46637
Software Genérico Networking
9.8
CRITICAL
EPSS
0.4%
2022 2 PoCs

Prolink router PRS1841 was discovered to contain hardcoded credentials for its Telnet and FTP services.

CVE-2022-1388
🔥 KEV BIG-IP Networking ⚡ nuclei
9.8
CRITICAL
EPSS
94.5%
2022 CWE-306 87 PoCs

On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13.1.x versions prior to 13.1.5, and all 12.1.x and 11.6.x versions, undisclosed requests may bypass iControl REST authentication. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated

CVE-2022-30271
Software Genérico Networking
9.8
CRITICAL
EPSS
0.2%
2022 1 PoC

The Motorola ACE1000 RTU through 2022-05-02 ships with a hardcoded SSH private key and initialization scripts (such as /etc/init.d/sshd_service) only generate a new key if no private-key file exists. Thus, this hardcoded key is likely to be used by default.

CVE-2022-4873
NF20 Networking
9.8
CRITICAL
EPSS
2.1%
2022 1 PoC

On Netcomm router models NF20MESH, NF20, and NL1902 a stack based buffer overflow affects the sessionKey parameter. By providing a specific number of bytes, the instruction pointer is able to be overwritten on the stack and crashes the application at a known location.

CVE-2022-3236
🔥 KEV Sophos Firewall Networking ⚡ nuclei
9.8
CRITICAL
EPSS
92.8%
2022 0 PoCs

A code injection vulnerability in the User Portal and Webadmin allows a remote attacker to execute code in Sophos Firewall version v19.0 MR1 and older.

CVE-2022-42475
🔥 KEV FortiProxy Networking
9.3
CRITICAL
EPSS
94.0%
2022 CWE-197 10 PoCs

A heap-based buffer overflow vulnerability [CWE-122] in FortiOS SSL-VPN 7.2.0 through 7.2.2, 7.0.0 through 7.0.8, 6.4.0 through 6.4.10, 6.2.0 through 6.2.11, 6.0.15 and earlier and FortiProxy SSL-VPN 7.2.0 through 7.2.1, 7.0.7 and earlier may allow a remote unauthenticated attacker to execute arbitrary code or commands via specifically crafted requests.

CVE-2022-50803
JF511-TV Networking
9.3
CRITICAL
EPSS
0.1%
2022 CWE-1392 1 PoC

JM-DATA ONU JF511-TV version 1.0.67 uses default credentials that allow attackers to gain unauthorized access to the device with administrative privileges.

CVE-2022-37337
Orbi Router RBR750 Web Networking
9.1
CRITICAL
EPSS
0.7%
2022 CWE-78 3 PoCs

A command execution vulnerability exists in the access control functionality of Netgear Orbi Router RBR750 4.6.8.5. A specially-crafted HTTP request can lead to arbitrary command execution. An attacker can make an authenticated HTTP request to trigger this vulnerability.

CVE-2022-26007
InRouter302 Networking
9.1
CRITICAL
EPSS
3.5%
2022 CWE-77 1 PoC

An OS command injection vulnerability exists in the console factory functionality of InHand Networks InRouter302 V3.5.4. A specially-crafted network request can lead to command execution. An attacker can send a sequence of requests to trigger this vulnerability.

CVE-2022-26002
InRouter302 Networking
9.1
CRITICAL
EPSS
7.7%
2022 CWE-121 1 PoC

A stack-based buffer overflow vulnerability exists in the console factory functionality of InHand Networks InRouter302 V3.5.4. A specially-crafted network request can lead to remote code execution. An attacker can send a sequence of malicious packets to trigger this vulnerability.

CVE-2022-45768
Software Genérico Networking
8.8
HIGH
EPSS
4.5%
2022 1 PoC

Command Injection vulnerability in Edimax Technology Co., Ltd. Wireless Router N300 Firmware BR428nS v3 allows attacker to execute arbitrary code via the formWlanMP function.

CVE-2022-27645
R6700v3 Networking Cloud
8.8
HIGH
EPSS
0.1%
2022 CWE-306 1 PoC

This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of NETGEAR R6700v3 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within readycloud_control.cgi. The issue results from the lack of authentication prior to allowing access to functionality. An attacker can leverage this vulnerability to execute code in the context of root. Was ZDI-CAN-15762.

CVE-2022-45313
Software Genérico Networking
8.8
HIGH
EPSS
12.9%
2022 1 PoC

Mikrotik RouterOs before stable v7.5 was discovered to contain an out-of-bounds read in the hotspot process. This vulnerability allows attackers to execute arbitrary code via a crafted nova message.