3303 vulnerabilidades · Networking Orden: CVSS EPSS Año ID
CVE-2015-1437
Software Genérico Web Networking
N/A
UNKNOWN
EPSS
0.4%
2015 1 PoC

Multiple cross-site scripting (XSS) vulnerabilities in Asus RT-N10+ D1 router with firmware 2.1.1.1.70 allow remote attackers to inject arbitrary web script or HTML via the flag parameter to (1) result_of_get_changed_status.asp or (2) error_page.htm.

CVE-2021-25101
Anti-Malware Security and Brute-Force Firewall Web Networking Windows
N/A
UNKNOWN
EPSS
0.2%
2021 CWE-79 1 PoC

The Anti-Malware Security and Brute-Force Firewall WordPress plugin before 4.20.94 does not sanitise and escape the POST data before outputting it back in attributes of an admin page, leading to a Reflected Cross-Site scripting. Due to the presence of specific parameter value, available to admin users, this can only be exploited by an admin against another admin user.

CVE-2021-20144
Gryphon Tower router Networking
N/A
UNKNOWN
EPSS
7.8%
2021 1 PoC

An unauthenticated command injection vulnerability exists in the parameters of operation 49 in the controller_server service on Gryphon Tower routers. An unauthenticated remote attacker on the same network can execute commands as root on the device by sending a specially crafted malicious packet to the controller_server service on port 9999.

CVE-2021-39474
Software Genérico Networking
N/A
UNKNOWN
EPSS
2.5%
2021 1 PoC

Vulnerability in the product Docsis 3.0 UBC1319BA00 Router supported affected version 1319010201r009. The vulnerability allows an attacker with privileges and network access through the ping.cmd component to execute commands on the device.

CVE-2015-1459
Software Genérico Web Networking
N/A
UNKNOWN
EPSS
0.4%
2015 1 PoC

Cross-site scripting (XSS) vulnerability in Fortinet FortiAuthenticator 3.0.0 allows remote attackers to inject arbitrary web script or HTML via the operation parameter to cert/scep/.

CVE-2021-22122
Fortinet FortiWeb Web Networking ⚡ nuclei
N/A
UNKNOWN
EPSS
55.6%
2021 0 PoCs

An improper neutralization of input during web page generation in FortiWeb GUI interface 6.3.0 through 6.3.7 and version before 6.2.4 may allow an unauthenticated, remote attacker to perform a reflected cross site scripting attack (XSS) by injecting malicious payload in different vulnerable API end-points.

CVE-2014-2718
Software Genérico Networking
N/A
UNKNOWN
EPSS
0.2%
2014 3 PoCs

ASUS RT-AC68U, RT-AC66R, RT-AC66U, RT-AC56R, RT-AC56U, RT-N66R, RT-N66U, RT-N56R, RT-N56U, and possibly other RT-series routers before firmware 3.0.0.4.376.x do not verify the integrity of firmware (1) update information or (2) downloaded updates, which allows man-in-the-middle (MITM) attackers to execute arbitrary code via a crafted image.

CVE-2015-6361
Software Genérico Networking
N/A
UNKNOWN
EPSS
0.5%
2015 1 PoC

The administrative web interface on Cisco DPC3939 (XB3) devices with firmware 121109aCMCST allows remote authenticated users to execute arbitrary commands via unspecified fields, aka Bug ID CSCuw86170.

CVE-2021-27932
Software Genérico Networking
N/A
UNKNOWN
EPSS
0.1%
2021 1 PoC

Stormshield Network Security (SNS) VPN SSL Client 2.1.0 through 2.8.0 has Insecure Permissions.

CVE-2015-4766
Software Genérico Networking Database
N/A
UNKNOWN
EPSS
0.2%
2015 1 PoC

Unspecified vulnerability in Oracle MySQL Server 5.6.25 and earlier allows local users to affect availability via unknown vectors related to Server : Security : Firewall.

CVE-2021-33965
Software Genérico Web Networking
N/A
UNKNOWN
EPSS
3.8%
2021 1 PoC

China Mobile An Lianbao WF-1 V1.0.1 router provides a web interface /api/ZRMesh/set_ZRMesh which receives parameters by POST request, and the parameter mesh_enable and mesh_device have a command injection vulnerability. An attacker can use the vulnerability to execute remote commands.

CVE-2021-20146
Gryphon Tower router Networking
N/A
UNKNOWN
EPSS
1.5%
2021 1 PoC

An unprotected ssh private key exists on the Gryphon devices which could be used to achieve root access to a server affiliated with Gryphon's development and infrastructure. At the time of discovery, the ssh key could be used to login to the development server hosted in Amazon Web Services.

CVE-2007-1258
Software Genérico Networking
N/A
UNKNOWN
EPSS
0.6%
2007 1 PoC

Unspecified vulnerability in Cisco IOS 12.2SXA, SXB, SXD, and SXF; and the MSFC2, MSFC2a and MSFC3 running in Hybrid Mode on Cisco Catalyst 6000, 6500 and Cisco 7600 series systems; allows remote attackers on a local network segment to cause a denial of service (software reload) via a certain MPLS packet.

CVE-2014-3115
Software Genérico Web Networking
N/A
UNKNOWN
EPSS
0.2%
2014 1 PoC

Multiple cross-site request forgery (CSRF) vulnerabilities in the web administration console in Fortinet FortiWeb before 5.2.0 allow remote attackers to hijack the authentication of administrators via system/config/adminadd and other unspecified vectors.

CVE-2015-2639
Software Genérico Networking Database
N/A
UNKNOWN
EPSS
0.3%
2015 1 PoC

Unspecified vulnerability in Oracle MySQL Server 5.6.24 and earlier allows remote authenticated users to affect integrity via unknown vectors related to Server : Security : Firewall.

CVE-2023-45285
cmd/go Web Networking
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

Using go get to fetch a module with the ".git" suffix may unexpectedly fallback to the insecure "git://" protocol if the module is unavailable via the secure "https://" and "git+ssh://" protocols, even if GOINSECURE is not set for said module. This only affects users who are not using the module proxy and are fetching modules directly (i.e. GOPROXY=off).

CVE-2021-31814
Software Genérico Networking
N/A
UNKNOWN
EPSS
0.0%
2021 2 PoCs

In Stormshield 1.1.0, and 2.1.0 through 2.9.0, an attacker can block a client from accessing the VPN and can obtain sensitive information through the SN VPN SSL Client.

CVE-2021-43282
Software Genérico Networking
N/A
UNKNOWN
EPSS
0.2%
2021 1 PoC

An issue was discovered on Victure WR1200 devices through 1.0.3. The default Wi-Fi WPA2 key is advertised to anyone within Wi-Fi range through the router's MAC address. The device default Wi-Fi password corresponds to the last 4 bytes of the MAC address of its 2.4 GHz network interface controller (NIC). An attacker within scanning range of the Wi-Fi network can thus scan for Wi-Fi networks to obtain the default key.

CVE-2015-2924
Software Genérico Networking
N/A
UNKNOWN
EPSS
0.6%
2015 1 PoC

The receive_ra function in rdisc/nm-lndp-rdisc.c in the Neighbor Discovery (ND) protocol implementation in the IPv6 stack in NetworkManager 1.x allows remote attackers to reconfigure a hop-limit setting via a small hop_limit value in a Router Advertisement (RA) message, a similar issue to CVE-2015-2922.

CVE-2021-3014
Software Genérico Web Networking
N/A
UNKNOWN
EPSS
0.5%
2021 1 PoC

In MikroTik RouterOS through 2021-01-04, the hotspot login page is vulnerable to reflected XSS via the target parameter.