188 vulnerabilidades · Networking Orden: CVSS EPSS Año ID
CVE-2024-8637
Chrome Networking
8.8
HIGH
EPSS
0.3%
2024 CWE-416 1 PoC

Use after free in Media Router in Google Chrome on Android prior to 128.0.6613.137 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVE-2024-48441
Software Genérico Networking
8.8
HIGH
EPSS
0.3%
2024 2 PoCs

Wuhan Tianyu Information Industry Co., Ltd Tianyu CPE Router CommonCPExCPETS_v3.2.468.11.04_P4 was discovered to contain a command injection vulnerability via the component at_command.asp.

CVE-2024-48416
Software Genérico Networking
8.8
HIGH
EPSS
0.2%
2024 1 PoC

Edimax AC1200 Wi-Fi 5 Dual-Band Router BR-6476AC 1.06 is vulnerable to Buffer Overflow via /goform/fromSetLanDhcpsClientbinding.

CVE-2024-1655
ExpertWiFi EBM63 Networking
8.8
HIGH
EPSS
14.6%
2024 CWE-78 1 PoC

Certain ASUS WiFi routers models has an OS Command Injection vulnerability, allowing an authenticated remote attacker to execute arbitrary system commands by sending a specially crafted request.

CVE-2024-7479
Remote Full Client Networking Windows
8.8
HIGH
EPSS
5.9%
2024 CWE-347 2 PoCs

Improper verification of cryptographic signature during installation of a VPN driver via the TeamViewer_service.exe component of TeamViewer Remote Clients prior version 15.58.4 for Windows allows an attacker with local unprivileged access on a Windows system to elevate their privileges and install drivers.

CVE-2024-40119
Software Genérico Web Networking
8.8
HIGH
EPSS
7.0%
2024 2 PoCs

Nepstech Wifi Router xpon (terminal) model NTPL-Xpon1GFEVN v.1.0 Firmware V2.0.1 contains a Cross-Site Request Forgery (CSRF) vulnerability in the password change function, which allows remote attackers to change the admin password without the user's consent, leading to a potential account takeover.

CVE-2024-48420
Software Genérico Networking
8.8
HIGH
EPSS
0.2%
2024 1 PoC

Edimax AC1200 Wi-Fi 5 Dual-Band Router BR-6476AC 1.06 is vulnerable to Buffer Overflow via /goform/getWifiBasic.

CVE-2024-30973
Software Genérico Networking
8.8
HIGH
EPSS
0.8%
2024 2 PoCs

An issue in V-SOL G/EPON ONU HG323AC-B with firmware version V2.0.08-210715 allows an attacker to execute arbtirary code and obtain sensitive information via crafted POST request to /boaform/getASPdata/formFirewall, /boaform/getASPdata/formAcc.

CVE-2024-54780
Software Genérico Networking
8.8
HIGH
EPSS
8.1%
2024 1 PoC

Netgate pfSense CE (prior to 2.8.0 beta release) and corresponding Plus builds are vulnerable to command injection in the OpenVPN widget due to improper sanitization of user-supplied input to the OpenVPN management interface. An authenticated attacker can exploit this vulnerability by injecting arbitrary OpenVPN management commands via the remipp parameter.

CVE-2024-57046
Software Genérico Networking ⚡ nuclei
8.8
HIGH
EPSS
46.7%
2024 1 PoC

A vulnerability in the Netgear DGN2200 router with firmware version v1.0.0.46 and earlier permits unauthorized individuals to bypass the authentication. When adding "?x=1.gif" to the the requested url, it will be recognized as passing the authentication.

CVE-2024-11075
SICK Incoming Goods Suite DevOps Networking
8.8
HIGH
EPSS
0.1%
2024 CWE-250 1 PoC

A vulnerability in the Incoming Goods Suite allows a user with unprivileged access to the underlying system (e.g. local or via SSH) a privilege escalation to the administrative level due to the usage of component vendor Docker images running with root permissions. Exploiting this misconfiguration leads to the fact that an attacker can gain administrative control. over the whole system.

CVE-2024-29366
Software Genérico Networking
8.8
HIGH
EPSS
0.3%
2024 1 PoC

A command injection vulnerability exists in the cgibin binary in DIR-845L router firmware <= v1.01KRb03.

CVE-2024-42658
Software Genérico Networking
8.8
HIGH
EPSS
14.4%
2024 2 PoCs

An issue in wishnet Nepstech Wifi Router NTPL-XPON1GFEVN v1.0 allows a remote attacker to obtain sensitive information via the cookie's parameter

CVE-2024-20295
Cisco Unified Computing System (Standalone) Networking
8.8
HIGH
EPSS
0.6%
2024 CWE-78 1 PoC

A vulnerability in the CLI of the Cisco Integrated Management Controller (IMC) could allow an authenticated, local attacker to perform command injection attacks on the underlying operating system and elevate privileges to root. To exploit this vulnerability, the attacker must have read-only or higher privileges on an affected device. This vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by submitting a crafted CLI command. A successful exploit could allow the attacker to elevate privileges to root.

CVE-2024-48418
Software Genérico Networking
8.8
HIGH
EPSS
0.1%
2024 1 PoC

In Edimax AC1200 Wi-Fi 5 Dual-Band Router BR-6476AC 1.06, the request /goform/fromSetDDNS does not properly handle special characters in any of user provided parameters, allowing an attacker with access to the web interface to inject and execute arbitrary shell commands.

CVE-2024-48440
Software Genérico Networking
8.8
HIGH
EPSS
0.3%
2024 2 PoCs

Shenzhen Tuoshi Network Communications Co.,Ltd 5G CPE Router NR500-EA RG500UEAABxCOMSLICv3.2.2543.12.18 was discovered to contain a command injection vulnerability via the component at_command.asp.

CVE-2024-48419
Software Genérico Networking
8.8
HIGH
EPSS
3.6%
2024 1 PoC

Edimax AC1200 Wi-Fi 5 Dual-Band Router BR-6476AC 1.06 suffers from Command Injection issues in /bin/goahead. Specifically, these issues can be triggered through /goform/tracerouteDiagnosis, /goform/pingDiagnosis, and /goform/fromSysToolPingCmd Each of these issues allows an attacker with access to the web interface to inject and execute arbitrary shell commands, with "root" privileges.

CVE-2024-11664
eNMS Networking
8.7
HIGH
EPSS
3.8%
2024 CWE-22 1 PoC

A vulnerability, which was classified as critical, has been found in eNMS up to 4.2. Affected by this issue is the function multiselect_filtering of the file eNMS/controller.py of the component TGZ File Handler. The manipulation leads to path traversal. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The patch is identified as 22b0b443acca740fc83b5544165c1f53eff3f529. It is recommended to apply a patch to fix this issue.

CVE-2024-20356
Cisco Unified Computing System (Standalone) Networking
8.7
HIGH
EPSS
43.4%
2024 CWE-78 2 PoCs

A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC) could allow an authenticated, remote attacker with Administrator-level privileges to perform command injection attacks on an affected system and elevate their privileges to root. This vulnerability is due to insufficient user input validation. An attacker could exploit this vulnerability by sending crafted commands to the web-based management interface of the affected software. A successful exploit could allow the attacker to elevate their privileges to root.

CVE-2024-3393
🔥 KEV Cloud NGFW Networking Cloud
8.7
HIGH
EPSS
77.7%
2024 CWE-754 2 PoCs

A Denial of Service vulnerability in the DNS Security feature of Palo Alto Networks PAN-OS software allows an unauthenticated attacker to send a malicious packet through the data plane of the firewall that reboots the firewall. Repeated attempts to trigger this condition will cause the firewall to enter maintenance mode.