3303 vulnerabilidades · Networking Orden: CVSS EPSS Año ID
CVE-2007-6276
Software Genérico Networking
N/A
UNKNOWN
EPSS
14.0%
2007 1 PoC

The accept_connections function in the virtual private network daemon (vpnd) in Apple Mac OS X 10.5 before 10.5.4 allows remote attackers to cause a denial of service (divide-by-zero error and daemon crash) via a crafted load balancing packet to UDP port 4112.

CVE-2007-4752
Software Genérico Networking
N/A
UNKNOWN
EPSS
2.3%
2007 1 PoC

ssh in OpenSSH before 4.7 does not properly handle when an untrusted cookie cannot be created and uses a trusted X11 cookie instead, which allows attackers to violate intended policy and gain privileges by causing an X client to be treated as trusted.

CVE-2014-4927
Software Genérico Web Networking
N/A
UNKNOWN
EPSS
17.5%
2014 1 PoC

Buffer overflow in ACME micro_httpd, as used in D-Link DSL2750U and DSL2740U and NetGear WGR614 and MR-ADSL-DG834 routers allows remote attackers to cause a denial of service (crash) via a long string in the URI in a GET request.

CVE-2013-0343
Software Genérico Networking
N/A
UNKNOWN
EPSS
0.5%
2013 3 PoCs

The ipv6_create_tempaddr function in net/ipv6/addrconf.c in the Linux kernel through 3.8 does not properly handle problems with the generation of IPv6 temporary addresses, which allows remote attackers to cause a denial of service (excessive retries and address-generation outage), and consequently obtain sensitive information, via ICMPv6 Router Advertisement (RA) messages.

CVE-2023-33621
Software Genérico Networking
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

GL.iNET GL-AR750S-Ext firmware v3.215 inserts the admin authentication token into a GET request when the OpenVPN Server config file is downloaded. The token is then left in the browser history or access logs, potentially allowing attackers to bypass authentication via session replay.

CVE-2021-20132
Quagga Services on D-Link DIR-2640 Routers Networking
N/A
UNKNOWN
EPSS
0.5%
2021 1 PoC

Quagga Services on D-Link DIR-2640 less than or equal to version 1.11B02 use default hard-coded credentials, which can allow a remote attacker to gain administrative access to the zebra or ripd those services. Both are running with root privileges on the router (i.e., as the "admin" user, UID 0).

CVE-2021-41653
Software Genérico Networking ⚡ nuclei
N/A
UNKNOWN
EPSS
91.9%
2021 3 PoCs

The PING function on the TP-Link TL-WR840N EU v5 router with firmware through TL-WR840N(EU)_V5_171211 is vulnerable to remote code execution via a crafted payload in an IP address input field.

CVE-2021-24295
Spam protection, AntiSpam, FireWall by CleanTalk Web Networking Database Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
40.6%
2021 CWE-89 1 PoC

It was possible to exploit an Unauthenticated Time-Based Blind SQL Injection vulnerability in the Spam protection, AntiSpam, FireWall by CleanTalk WordPress Plugin before 5.153.4. The update_log function in lib/Cleantalk/ApbctWP/Firewall/SFW.php included a vulnerable query that could be injected via the User-Agent Header by manipulating the cookies set by the Spam protection, AntiSpam, FireWall by CleanTalk WordPress plugin before 5.153.4, sending an initial request to obtain a ct_sfw_pass_key cookie and then manually setting a separate ct_sfw_passed cookie and disallowing it from being reset.

CVE-2013-5218
Software Genérico Web Networking
N/A
UNKNOWN
EPSS
0.8%
2013 2 PoCs

Cross-site scripting (XSS) vulnerability on the HOT HOTBOX router with software 2.1.11 allows remote attackers to inject arbitrary web script or HTML via a crafted DHCP Host Name option, which is not properly handled during rendering of the DHCP table in wlanAccess.asp.

CVE-2021-36708
Software Genérico Networking
N/A
UNKNOWN
EPSS
0.3%
2021 1 PoC

In ProLink PRC2402M V1.0.18 and older, the set_sys_init function in the login.cgi binary allows an attacker to reset the password to the administrative interface of the router.

CVE-2014-2721
Software Genérico Networking
N/A
UNKNOWN
EPSS
1.1%
2014 1 PoC

In FortiBalancer 400, 1000, 2000 and 3000, a platform-specific remote access vulnerability has been discovered that may allow a remote user to gain privileged access to affected systems using SSH. The vulnerability is caused by a configuration error, and is not the result of an underlying SSH defect.

CVE-2013-4434
Software Genérico Networking
N/A
UNKNOWN
EPSS
1.9%
2013 1 PoC

Dropbear SSH Server before 2013.59 generates error messages for a failed logon attempt with different time delays depending on whether the user account exists, which allows remote attackers to discover valid usernames.

CVE-2021-41441
Software Genérico Networking
N/A
UNKNOWN
EPSS
0.2%
2021 1 PoC

A DoS attack in the web application of D-Link DIR-X1860 before v1.10WWB09_Beta allows a remote unauthenticated attacker to reboot the router via sending a specially crafted URL to an authenticated victim. The authenticated victim need to visit this URL, for the router to reboot.

CVE-2021-31604
Software Genérico Web Networking
N/A
UNKNOWN
EPSS
0.1%
2021 1 PoC

furlongm openvpn-monitor through 1.1.3 allows CSRF to disconnect an arbitrary client.

CVE-2013-3091
Software Genérico Web Networking
N/A
UNKNOWN
EPSS
5.0%
2013 1 PoC

An Authentication Bypass vulnerability in Belkin N300 (F7D7301v1) router allows remote attackers to bypass authentication using "Javascript debugging."

CVE-2021-43483
Software Genérico Networking
N/A
UNKNOWN
EPSS
0.1%
2021 1 PoC

An Access Control vulnerability exists in CLARO KAON CG3000 1.00.67 in the router configuration, which could allow a malicious user to read or update the configuraiton without authentication.

CVE-2007-1330
Software Genérico Networking
N/A
UNKNOWN
EPSS
0.2%
2007 1 PoC

Comodo Firewall Pro (CFP) (formerly Comodo Personal Firewall) 2.4.18.184 and earlier allows local users to bypass driver protections on the HKLM\SYSTEM\Software\Comodo\Personal Firewall registry key by guessing the name of a named pipe under \Device\NamedPipe\OLE and attempting to open it multiple times.

CVE-2014-4155
Software Genérico Web Networking
N/A
UNKNOWN
EPSS
0.3%
2014 3 PoCs

Cross-site request forgery (CSRF) vulnerability in the ZTE ZXV10 W300 router with firmware W300V1.0.0a_ZRD_LK allows remote attackers to hijack the authentication of administrators for requests that change the admin password via a request to Forms/tools_admin_1.

CVE-2013-7306
Software Genérico Networking
N/A
UNKNOWN
EPSS
0.5%
2013 2 PoCs

The OSPF implementation on Brocade routers does not consider the possibility of duplicate Link State ID values in Link State Advertisement (LSA) packets before performing operations on the LSA database, which allows remote attackers to cause a denial of service (routing disruption) or obtain sensitive packet information via a crafted LSA packet, a related issue to CVE-2013-0149.

CVE-2023-33277
Software Genérico Networking
N/A
UNKNOWN
EPSS
0.1%
2023 2 PoCs

The web interface of Gira Giersiepen Gira KNX/IP-Router 3.1.3683.0 and 3.3.8.0 allows a remote attacker to read sensitive files via directory-traversal sequences in the URL.