3303 vulnerabilidades · Networking Orden: CVSS EPSS Año ID
CVE-2013-2681
Software Genérico Networking
N/A
UNKNOWN
EPSS
43.2%
2013 1 PoC

Cisco Linksys E4200 1.0.05 Build 7 devices contain a Security Bypass Vulnerability which could allow remote attackers to gain unauthorized access.

CVE-2019-7404
Software Genérico Web Networking
N/A
UNKNOWN
EPSS
0.8%
2019 2 PoCs

An issue was discovered on LG GAMP-7100, GAPM-7200, and GAPM-8000 routers. An unauthenticated user can read a log file via an HTTP request containing its full pathname, such as http://192.168.0.1/var/gapm7100_${today's_date}.log for reading a filename such as gapm7100_190101.log.

CVE-2013-4772
Software Genérico Networking Cloud
N/A
UNKNOWN
EPSS
0.1%
2013 1 PoC

D-Link DIR-505L SharePort Mobile Companion 1.01 and DIR-826L Wireless N600 Cloud Router 1.02 allows remote attackers to bypass authentication via a direct request when an authorized session is active.

CVE-2019-18909
ThinPro Linux Networking
N/A
UNKNOWN
EPSS
0.2%
2019 2 PoCs

The VPN software within HP ThinPro does not safely handle user supplied input, which may be leveraged by an attacker to inject commands that will execute with root privileges.

CVE-2019-14744
Software Genérico Networking
N/A
UNKNOWN
EPSS
1.3%
2019 2 PoCs

In KDE Frameworks KConfig before 5.61.0, malicious desktop files and configuration files lead to code execution with minimal user interaction. This relates to libKF5ConfigCore.so, and the mishandling of .desktop and .directory files, as demonstrated by a shell command on an Icon line in a .desktop file.

CVE-2014-4346
Software Genérico Web Networking
N/A
UNKNOWN
EPSS
0.8%
2014 1 PoC

Cross-site scripting (XSS) vulnerability in administration user interface in Citrix NetScaler Application Delivery Controller (ADC) and NetScaler Gateway (formerly Access Gateway Enterprise Edition) 10.1 before 10.1-126.12 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVE-2013-7183
Software Genérico Networking
N/A
UNKNOWN
EPSS
9.9%
2013 1 PoC

cgi-bin/reboot.cgi on Seowon Intech SWC-9100 routers allows remote attackers to (1) cause a denial of service (reboot) via a default_reboot action or (2) reset all configuration values via a factory_default action.

CVE-2019-3976
MikroTik RouterOS Networking
N/A
UNKNOWN
EPSS
1.4%
2019 CWE-23 1 PoC

RouterOS 6.45.6 Stable, RouterOS 6.44.5 Long-term, and below are vulnerable to an arbitrary directory creation vulnerability via the upgrade package's name field. If an authenticated user installs a malicious package then a directory could be created and the developer shell could be enabled.

CVE-2019-17506
Software Genérico Web Networking ⚡ nuclei
N/A
UNKNOWN
EPSS
93.8%
2019 0 PoCs

There are some web interfaces without authentication requirements on D-Link DIR-868L B1-2.03 and DIR-817LW A1-1.04 routers. An attacker can get the router's username and password (and other information) via a DEVICE.ACCOUNT value for SERVICES in conjunction with AUTHORIZED_GROUP=1%0a to getcfg.php. This could be used to control the router remotely.

CVE-2013-4659
Software Genérico Networking
N/A
UNKNOWN
EPSS
11.5%
2013 1 PoC

Buffer overflow in Broadcom ACSD allows remote attackers to execute arbitrary code via a long string to TCP port 5916. This component is used on routers of multiple vendors including ASUS RT-AC66U and TRENDnet TEW-812DRU.

CVE-2019-9555
Software Genérico Networking
N/A
UNKNOWN
EPSS
0.2%
2019 1 PoC

Sagemcom F@st 5260 routers using firmware version 0.4.39, in WPA mode, default to using a PSK that is generated from a 2-part wordlist of known values and a nonce with insufficient entropy. The number of possible PSKs is about 1.78 billion, which is too small.

CVE-2007-5583
Software Genérico Networking Cloud
N/A
UNKNOWN
EPSS
30.1%
2007 1 PoC

Cisco IP Phone 7940 with firmware P0S3-08-7-00 allows remote attackers to cause a denial of service ("486 Busy" responses or device reboot) via a sequence of SIP INVITE transactions in which the Request-URI lacks a user name, a different vulnerability than CVE-2007-4459.

CVE-2013-2684
Software Genérico Web Networking
N/A
UNKNOWN
EPSS
4.5%
2013 1 PoC

Cross-site Scripting (XSS) in Cisco Linksys E4200 1.0.05 Build 7 devices allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVE-2019-12174
Software Genérico Networking
N/A
UNKNOWN
EPSS
0.0%
2019 1 PoC

hide.me before 2.4.4 on macOS suffers from a privilege escalation vulnerability in the connectWithExecutablePath:configFilePath:configFileName method of the me_hide_vpnhelper.Helper class in the me.hide.vpnhelper macOS privilege helper tool. This method takes user-supplied input and can be used to escalate privileges, as well as obtain the ability to run any application on the system in the root context.

CVE-2019-14511
Software Genérico Networking
N/A
UNKNOWN
EPSS
0.8%
2019 1 PoC

Sphinx Technologies Sphinx 3.1.1 by default has no authentication and listens on 0.0.0.0, making it exposed to the internet (unless filtered by a firewall or reconfigured to listen to 127.0.0.1 only).

CVE-2019-20810
Software Genérico Networking
N/A
UNKNOWN
EPSS
0.1%
2019 2 PoCs

go7007_snd_init in drivers/media/usb/go7007/snd-go7007.c in the Linux kernel before 5.6 does not call snd_card_free for a failure path, which causes a memory leak, aka CID-9453264ef586.

CVE-2019-20004
Software Genérico Networking
N/A
UNKNOWN
EPSS
0.4%
2019 2 PoCs

An issue was discovered on Intelbras IWR 3000N 1.8.7 devices. When the administrator password is changed from a certain client IP address, administrative authorization remains available to any client at that IP address, leading to complete control of the router.

CVE-2013-7314
Software Genérico Networking
N/A
UNKNOWN
EPSS
2.5%
2013 2 PoCs

The OSPF implementation on NEC IP38X, IX1000, IX2000, and IX3000 routers does not consider the possibility of duplicate Link State ID values in Link State Advertisement (LSA) packets before performing operations on the LSA database, which allows remote attackers to cause a denial of service (routing disruption) or obtain sensitive packet information via a crafted LSA packet, a related issue to CVE-2013-0149.

CVE-2019-19824
Software Genérico Networking ⚡ nuclei
N/A
UNKNOWN
EPSS
89.5%
2019 3 PoCs

On certain TOTOLINK Realtek SDK based routers, an authenticated attacker may execute arbitrary OS commands via the sysCmd parameter to the boafrm/formSysCmd URI, even if the GUI (syscmd.htm) is not available. This allows for full control over the device's internals. This affects A3002RU through 2.0.0, A702R through 2.1.3, N301RT through 2.1.6, N302R through 3.4.0, N300RT through 3.4.0, N200RE through 4.0.0, N150RT through 3.4.0, N100RE through 3.4.0, and N302RE 2.0.2.

CVE-2019-14332
Software Genérico Networking
N/A
UNKNOWN
EPSS
0.1%
2019 1 PoC

An issue was discovered on D-Link 6600-AP and DWL-3600AP Ax 4.2.0.14 21/03/2019 devices. There is use of weak ciphers for SSH such as diffie-hellman-group1-sha1.