| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-28808 | Cri | 0.59 | 9.1 | 0.01 | Apr 11, 2023 | Some Hikvision Hybrid SAN/Cluster Storage products have an access control vulnerability which can be used to obtain the admin permission. The attacker can exploit the vulnerability by sending crafted messages to the affected devices. | ||
| CVE-2023-28250 | Cri | 0.64 | 9.8 | 0.02 | Apr 11, 2023 | Windows Pragmatic General Multicast (PGM) Remote Code Execution Vulnerability | ||
| CVE-2023-21554 | Cri | 0.74 | 9.8 | 0.95 | Apr 11, 2023 | Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability | ||
| CVE-2020-19802 | Cri | 0.64 | 9.8 | 0.01 | Apr 11, 2023 | File Upload vulnerability found in Milken DoyoCMS v.2.3 allows a remote attacker to execute arbitrary code via the upload file type parameter. | ||
| CVE-2022-41331 | Cri | 0.64 | 9.8 | 0.01 | Apr 11, 2023 | A missing authentication for critical function vulnerability [CWE-306] in FortiPresence infrastructure server before version 1.2.1 allows a remote, unauthenticated attacker to access the Redis and MongoDB instances via crafted authentication requests. | ||
| CVE-2023-27192 | Cri | 0.64 | 9.8 | 0.01 | Apr 11, 2023 | An issue found in DUALSPACE Super Secuirty v.2.3.7 allows an attacker to cause a denial of service via the key_wifi_safe_net_check_url, KEY_Cirus_scan_whitelist and KEY_AD_NEW_USER_AVOID_TIME parameters. | ||
| CVE-2023-27645 | Cri | 0.64 | 9.8 | 0.01 | Apr 11, 2023 | An issue found in POWERAMP audioplayer build 925 bundle play and build 954 allows a remote attacker to gain privileges via the reverb and EQ preset parameters. | ||
| CVE-2023-28489 | Cri | 0.64 | 9.8 | 0.03 | Apr 11, 2023 | A vulnerability has been identified in CP-8031 MASTER MODULE (All versions < CPCI85 V05), CP-8050 MASTER MODULE (All versions < CPCI85 V05). Affected devices are vulnerable to command injection via the web server port 443/tcp, if the parameter “Remote Operation” is enabled.… | ||
| CVE-2023-29492 | Cri | 0.76 | 9.8 | 0.03 | KEV | Apr 11, 2023 | Novi Survey before 8.9.43676 allows remote attackers to execute arbitrary code on the server in the context of the service account. This does not provide access to stored survey or response data. | |
| CVE-2023-28765 | Cri | 0.65 | 9.8 | 0.15 | Apr 11, 2023 | An attacker with basic privileges in SAP BusinessObjects Business Intelligence Platform (Promotion Management) - versions 420, 430, can get access to lcmbiar file and further decrypt the file. After this attacker can gain access to BI user’s passwords and depending on the… | ||
| CVE-2023-27497 | Cri | 0.65 | 10.0 | 0.01 | Apr 11, 2023 | Due to missing authentication and input sanitization of code the EventLogServiceCollector of SAP Diagnostics Agent - version 720, allows an attacker to execute malicious scripts on all connected Diagnostics Agents running on Windows. On successful exploitation, the attacker can… | ||
| CVE-2023-27267 | Cri | 0.60 | 9.0 | 0.14 | Apr 11, 2023 | Due to missing authentication and insufficient input validation, the OSCommand Bridge of SAP Diagnostics Agent - version 720, allows an attacker with deep knowledge of the system to execute scripts on all connected Diagnostics Agents. On successful exploitation, the attacker… | ||
| CVE-2023-27178 | Cri | 0.64 | 9.8 | 0.01 | Apr 10, 2023 | An arbitrary file upload vulnerability in the upload function of GDidees CMS 3.9.1 allows attackers to execute arbitrary code via a crafted file. | ||
| CVE-2023-27076 | Cri | 0.66 | 9.8 | 0.23 | Apr 10, 2023 | Command injection vulnerability found in Tenda G103 v.1.0.0.5 allows attacker to execute arbitrary code via a the language parameter. | ||
| CVE-2023-26070 | Cri | 0.64 | 9.8 | 0.01 | Apr 10, 2023 | Certain Lexmark devices through 2023-02-19 mishandle Input Validation (issue 4 of 4). | ||
| CVE-2023-26069 | Cri | 0.64 | 9.8 | 0.01 | Apr 10, 2023 | Certain Lexmark devices through 2023-02-19 mishandle Input Validation (issue 3 of 4). | ||
| CVE-2023-26068 | Cri | 0.68 | 9.8 | 0.12 | Apr 10, 2023 | Certain Lexmark devices through 2023-02-19 mishandle Input Validation (issue 2 of 4). | ||
| CVE-2023-26066 | Cri | 0.64 | 9.8 | 0.01 | Apr 10, 2023 | Certain Lexmark devices through 2023-02-19 have Improper Validation of an Array Index. | ||
| CVE-2023-26065 | Cri | 0.64 | 9.8 | 0.01 | Apr 10, 2023 | Certain Lexmark devices through 2023-02-19 have an Integer Overflow. | ||
| CVE-2023-26064 | Cri | 0.64 | 9.8 | 0.01 | Apr 10, 2023 | Certain Lexmark devices through 2023-02-19 have an Out-of-bounds Write. | ||
| CVE-2023-26063 | Cri | 0.64 | 9.8 | 0.01 | Apr 10, 2023 | Certain Lexmark devices through 2023-02-19 access a Resource By Using an Incompatible Type. | ||
| CVE-2022-46709 | Cri | 0.64 | 9.8 | 0.01 | Apr 10, 2023 | A memory corruption issue was addressed with improved state management. This issue is fixed in macOS Ventura 13, iOS 16. An app may be able to execute arbitrary code with kernel privileges | ||
| CVE-2023-27650 | Cri | 0.64 | 9.8 | 0.02 | Apr 10, 2023 | An issue found in APUS Group Launcher v.3.10.73 and v.3.10.88 allows a remote attacker to execute arbitrary code via the FONT_FILE parameter. | ||
| CVE-2023-29375 | Cri | 0.64 | 9.8 | 0.01 | Apr 10, 2023 | An issue was discovered in Progress Sitefinity 13.3 before 13.3.7647, 14.0 before 14.0.7736, 14.1 before 14.1.7826, 14.2 before 14.2.7930, and 14.3 before 14.3.8025. There is potentially dangerous file upload through the SharePoint connector. | ||
| CVE-2022-41976 | Cri | 0.64 | 9.9 | 0.02 | Apr 10, 2023 | An privilege escalation issue was discovered in Scada-LTS 2.7.1.1 build 2948559113 allows remote attackers, authenticated in the application as a low-privileged user to change role (e.g., to administrator) by updating their user profile. | ||
| CVE-2023-1478 | Cri | 0.64 | 9.8 | 0.01 | Apr 10, 2023 | The Hummingbird WordPress plugin before 3.4.2 does not validate the generated file path for page cache files before writing them, leading to a path traversal vulnerability in the page cache module. | ||
| CVE-2023-29216 | — | Cri | 0.64 | 9.8 | 0.02 | Apr 10, 2023 | In Apache Linkis <=1.3.1, because the parameters are not effectively filtered, the attacker uses the MySQL data source and malicious parameters to configure a new data source to trigger a deserialization vulnerability, eventually leading to remote code execution. Versions of… | |
| CVE-2023-29215 | — | Cri | 0.57 | 9.8 | 0.02 | Apr 10, 2023 | In Apache Linkis <=1.3.1, due to the lack of effective filtering of parameters, an attacker configuring malicious Mysql JDBC parameters in JDBC EengineConn Module will trigger a deserialization vulnerability and eventually lead to remote code execution. Therefore, the parameters… | |
| CVE-2023-27987 | — | Cri | 0.59 | 9.1 | 0.01 | Apr 10, 2023 | In Apache Linkis <=1.3.1, due to the default token generated by Linkis Gateway deployment being too simple, it is easy for attackers to obtain the default token for the attack. Generation rules should add random values. We recommend users upgrade the version of Linkis to… | |
| CVE-2023-27603 | — | Cri | 0.64 | 9.8 | 0.02 | Apr 10, 2023 | In Apache Linkis <=1.3.1, due to the Manager module engineConn material upload does not check the zip path, This is a Zip Slip issue, which will lead to a potential RCE vulnerability. We recommend users upgrade the version of Linkis to version 1.3.2. | |
| CVE-2023-27602 | — | Cri | 0.64 | 9.8 | 0.02 | Apr 10, 2023 | In Apache Linkis <=1.3.1, The PublicService module uploads files without restrictions on the path to the uploaded files, and file types. We recommend users upgrade the version of Linkis to version 1.3.2. For versions <=1.3.1, we suggest turning on the file path check… | |
| CVE-2023-27720 | Cri | 0.64 | 9.8 | 0.01 | Apr 9, 2023 | D-Link DIR878 1.30B08 was discovered to contain a stack overflow in the sub_48d630 function. This vulnerability allows attackers to cause a Denial of Service (DoS) or execute arbitrary code via a crafted payload. | ||
| CVE-2023-27719 | Cri | 0.64 | 9.8 | 0.01 | Apr 9, 2023 | D-Link DIR878 1.30B08 was discovered to contain a stack overflow in the sub_478360 function. This vulnerability allows attackers to cause a Denial of Service (DoS) or execute arbitrary code via a crafted payload. | ||
| CVE-2023-27718 | Cri | 0.64 | 9.8 | 0.01 | Apr 9, 2023 | D-Link DIR878 1.30B08 was discovered to contain a stack overflow in the sub_498308 function. This vulnerability allows attackers to cause a Denial of Service (DoS) or execute arbitrary code via a crafted payload. | ||
| CVE-2023-27033 | Cri | 0.64 | 9.8 | 0.01 | Apr 7, 2023 | Prestashop cdesigner v3.1.3 to v3.1.8 was discovered to contain a code injection vulnerability via the component CdesignerSaverotateModuleFrontController::initContent(). | ||
| CVE-2023-28706 | Cri | 0.57 | 9.8 | 0.03 | Apr 7, 2023 | Improper Control of Generation of Code ('Code Injection') vulnerability in Apache Software Foundation Apache Airflow Hive Provider.This issue affects Apache Airflow Hive Provider: before 6.0.0. | ||
| CVE-2023-29478 | Cri | 0.64 | 9.8 | 0.02 | Apr 7, 2023 | BiblioCraft before 2.4.6 does not sanitize path-traversal characters in filenames, allowing restricted write access to almost anywhere on the filesystem. This includes the Minecraft mods folder, which results in code execution. | ||
| CVE-2023-26978 | Cri | 0.64 | 9.8 | 0.02 | Apr 7, 2023 | TOTOlink A7100RU V7.4cu.2313_B20191024 was discovered to contain a command injection vulnerability via the pppoeAcName parameter at /setting/setWanIeCfg. | ||
| CVE-2023-26848 | Cri | 0.64 | 9.8 | 0.02 | Apr 7, 2023 | TOTOlink A7100RU(V7.4cu.2313_B20191024) was discovered to contain a command injection vulnerability via the org parameter at setting/delStaticDhcpRules. | ||
| CVE-2023-27021 | Cri | 0.64 | 9.8 | 0.01 | Apr 7, 2023 | Tenda AC10 US_AC10V4.0si_V16.03.10.13_cn was discovered to contain a stack overflow via the formSetFirewallCfg function. This vulnerability allows attackers to cause a Denial of Service (DoS) or execute arbitrary code via a crafted payload. | ||
| CVE-2023-27020 | Cri | 0.64 | 9.8 | 0.01 | Apr 7, 2023 | Tenda AC10 US_AC10V4.0si_V16.03.10.13_cn was discovered to contain a stack overflow via the saveParentControlInfo function. This vulnerability allows attackers to cause a Denial of Service (DoS) or execute arbitrary code via a crafted payload. | ||
| CVE-2023-27019 | Cri | 0.64 | 9.8 | 0.01 | Apr 7, 2023 | Tenda AC10 US_AC10V4.0si_V16.03.10.13_cn was discovered to contain a stack overflow via the sub_458FBC function. This vulnerability allows attackers to cause a Denial of Service (DoS) or execute arbitrary code via a crafted payload. | ||
| CVE-2023-27018 | Cri | 0.64 | 9.8 | 0.01 | Apr 7, 2023 | Tenda AC10 US_AC10V4.0si_V16.03.10.13_cn was discovered to contain a stack overflow via the sub_45EC1C function. This vulnerability allows attackers to cause a Denial of Service (DoS) or execute arbitrary code via a crafted payload. | ||
| CVE-2023-27017 | Cri | 0.64 | 9.8 | 0.01 | Apr 7, 2023 | Tenda AC10 US_AC10V4.0si_V16.03.10.13_cn was discovered to contain a stack overflow via the sub_45DC58 function. This vulnerability allows attackers to cause a Denial of Service (DoS) or execute arbitrary code via a crafted payload. | ||
| CVE-2023-27016 | Cri | 0.64 | 9.8 | 0.01 | Apr 7, 2023 | Tenda AC10 US_AC10V4.0si_V16.03.10.13_cn was discovered to contain a stack overflow via the R7WebsSecurityHandler function. This vulnerability allows attackers to cause a Denial of Service (DoS) or execute arbitrary code via a crafted payload. | ||
| CVE-2023-27015 | Cri | 0.64 | 9.8 | 0.01 | Apr 7, 2023 | Tenda AC10 US_AC10V4.0si_V16.03.10.13_cn was discovered to contain a stack overflow via the sub_4A75C0 function. This vulnerability allows attackers to cause a Denial of Service (DoS) or execute arbitrary code via a crafted payload. | ||
| CVE-2023-27014 | Cri | 0.64 | 9.8 | 0.01 | Apr 7, 2023 | Tenda AC10 US_AC10V4.0si_V16.03.10.13_cn was discovered to contain a stack overflow via the sub_46AC38 function. This vulnerability allows attackers to cause a Denial of Service (DoS) or execute arbitrary code via a crafted payload. | ||
| CVE-2023-27013 | Cri | 0.64 | 9.8 | 0.01 | Apr 7, 2023 | Tenda AC10 US_AC10V4.0si_V16.03.10.13_cn was discovered to contain a stack overflow via the get_parentControl_list_Info function. This vulnerability allows attackers to cause a Denial of Service (DoS) or execute arbitrary code via a crafted payload. | ||
| CVE-2023-27012 | Cri | 0.64 | 9.8 | 0.01 | Apr 7, 2023 | Tenda AC10 US_AC10V4.0si_V16.03.10.13_cn was discovered to contain a stack overflow via the setSchedWifi function. This vulnerability allows attackers to cause a Denial of Service (DoS) or execute arbitrary code via a crafted payload. | ||
| CVE-2023-25220 | Cri | 0.64 | 9.8 | 0.01 | Apr 7, 2023 | Tenda AC5 US_AC5V1.0RTL_V15.03.06.28 was discovered to contain a stack overflow via the add_white_node function. This vulnerability allows attackers to cause a Denial of Service (DoS) or execute arbitrary code via a crafted payload. |
- risk 0.59cvss 9.1epss 0.01
Some Hikvision Hybrid SAN/Cluster Storage products have an access control vulnerability which can be used to obtain the admin permission. The attacker can exploit the vulnerability by sending crafted messages to the affected devices.
- risk 0.64cvss 9.8epss 0.02
Windows Pragmatic General Multicast (PGM) Remote Code Execution Vulnerability
- risk 0.74cvss 9.8epss 0.95
Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability
- risk 0.64cvss 9.8epss 0.01
File Upload vulnerability found in Milken DoyoCMS v.2.3 allows a remote attacker to execute arbitrary code via the upload file type parameter.
- risk 0.64cvss 9.8epss 0.01
A missing authentication for critical function vulnerability [CWE-306] in FortiPresence infrastructure server before version 1.2.1 allows a remote, unauthenticated attacker to access the Redis and MongoDB instances via crafted authentication requests.
- risk 0.64cvss 9.8epss 0.01
An issue found in DUALSPACE Super Secuirty v.2.3.7 allows an attacker to cause a denial of service via the key_wifi_safe_net_check_url, KEY_Cirus_scan_whitelist and KEY_AD_NEW_USER_AVOID_TIME parameters.
- risk 0.64cvss 9.8epss 0.01
An issue found in POWERAMP audioplayer build 925 bundle play and build 954 allows a remote attacker to gain privileges via the reverb and EQ preset parameters.
- risk 0.64cvss 9.8epss 0.03
A vulnerability has been identified in CP-8031 MASTER MODULE (All versions < CPCI85 V05), CP-8050 MASTER MODULE (All versions < CPCI85 V05). Affected devices are vulnerable to command injection via the web server port 443/tcp, if the parameter “Remote Operation” is enabled.…
- risk 0.76cvss 9.8epss 0.03
Novi Survey before 8.9.43676 allows remote attackers to execute arbitrary code on the server in the context of the service account. This does not provide access to stored survey or response data.
- risk 0.65cvss 9.8epss 0.15
An attacker with basic privileges in SAP BusinessObjects Business Intelligence Platform (Promotion Management) - versions 420, 430, can get access to lcmbiar file and further decrypt the file. After this attacker can gain access to BI user’s passwords and depending on the…
- risk 0.65cvss 10.0epss 0.01
Due to missing authentication and input sanitization of code the EventLogServiceCollector of SAP Diagnostics Agent - version 720, allows an attacker to execute malicious scripts on all connected Diagnostics Agents running on Windows. On successful exploitation, the attacker can…
- risk 0.60cvss 9.0epss 0.14
Due to missing authentication and insufficient input validation, the OSCommand Bridge of SAP Diagnostics Agent - version 720, allows an attacker with deep knowledge of the system to execute scripts on all connected Diagnostics Agents. On successful exploitation, the attacker…
- risk 0.64cvss 9.8epss 0.01
An arbitrary file upload vulnerability in the upload function of GDidees CMS 3.9.1 allows attackers to execute arbitrary code via a crafted file.
- risk 0.66cvss 9.8epss 0.23
Command injection vulnerability found in Tenda G103 v.1.0.0.5 allows attacker to execute arbitrary code via a the language parameter.
- risk 0.64cvss 9.8epss 0.01
Certain Lexmark devices through 2023-02-19 mishandle Input Validation (issue 4 of 4).
- risk 0.64cvss 9.8epss 0.01
Certain Lexmark devices through 2023-02-19 mishandle Input Validation (issue 3 of 4).
- risk 0.68cvss 9.8epss 0.12
Certain Lexmark devices through 2023-02-19 mishandle Input Validation (issue 2 of 4).
- risk 0.64cvss 9.8epss 0.01
Certain Lexmark devices through 2023-02-19 have Improper Validation of an Array Index.
- risk 0.64cvss 9.8epss 0.01
Certain Lexmark devices through 2023-02-19 have an Integer Overflow.
- risk 0.64cvss 9.8epss 0.01
Certain Lexmark devices through 2023-02-19 have an Out-of-bounds Write.
- risk 0.64cvss 9.8epss 0.01
Certain Lexmark devices through 2023-02-19 access a Resource By Using an Incompatible Type.
- risk 0.64cvss 9.8epss 0.01
A memory corruption issue was addressed with improved state management. This issue is fixed in macOS Ventura 13, iOS 16. An app may be able to execute arbitrary code with kernel privileges
- risk 0.64cvss 9.8epss 0.02
An issue found in APUS Group Launcher v.3.10.73 and v.3.10.88 allows a remote attacker to execute arbitrary code via the FONT_FILE parameter.
- risk 0.64cvss 9.8epss 0.01
An issue was discovered in Progress Sitefinity 13.3 before 13.3.7647, 14.0 before 14.0.7736, 14.1 before 14.1.7826, 14.2 before 14.2.7930, and 14.3 before 14.3.8025. There is potentially dangerous file upload through the SharePoint connector.
- risk 0.64cvss 9.9epss 0.02
An privilege escalation issue was discovered in Scada-LTS 2.7.1.1 build 2948559113 allows remote attackers, authenticated in the application as a low-privileged user to change role (e.g., to administrator) by updating their user profile.
- risk 0.64cvss 9.8epss 0.01
The Hummingbird WordPress plugin before 3.4.2 does not validate the generated file path for page cache files before writing them, leading to a path traversal vulnerability in the page cache module.
- risk 0.64cvss 9.8epss 0.02
In Apache Linkis <=1.3.1, because the parameters are not effectively filtered, the attacker uses the MySQL data source and malicious parameters to configure a new data source to trigger a deserialization vulnerability, eventually leading to remote code execution. Versions of…
- risk 0.57cvss 9.8epss 0.02
In Apache Linkis <=1.3.1, due to the lack of effective filtering of parameters, an attacker configuring malicious Mysql JDBC parameters in JDBC EengineConn Module will trigger a deserialization vulnerability and eventually lead to remote code execution. Therefore, the parameters…
- risk 0.59cvss 9.1epss 0.01
In Apache Linkis <=1.3.1, due to the default token generated by Linkis Gateway deployment being too simple, it is easy for attackers to obtain the default token for the attack. Generation rules should add random values. We recommend users upgrade the version of Linkis to…
- risk 0.64cvss 9.8epss 0.02
In Apache Linkis <=1.3.1, due to the Manager module engineConn material upload does not check the zip path, This is a Zip Slip issue, which will lead to a potential RCE vulnerability. We recommend users upgrade the version of Linkis to version 1.3.2.
- risk 0.64cvss 9.8epss 0.02
In Apache Linkis <=1.3.1, The PublicService module uploads files without restrictions on the path to the uploaded files, and file types. We recommend users upgrade the version of Linkis to version 1.3.2. For versions <=1.3.1, we suggest turning on the file path check…
- risk 0.64cvss 9.8epss 0.01
D-Link DIR878 1.30B08 was discovered to contain a stack overflow in the sub_48d630 function. This vulnerability allows attackers to cause a Denial of Service (DoS) or execute arbitrary code via a crafted payload.
- risk 0.64cvss 9.8epss 0.01
D-Link DIR878 1.30B08 was discovered to contain a stack overflow in the sub_478360 function. This vulnerability allows attackers to cause a Denial of Service (DoS) or execute arbitrary code via a crafted payload.
- risk 0.64cvss 9.8epss 0.01
D-Link DIR878 1.30B08 was discovered to contain a stack overflow in the sub_498308 function. This vulnerability allows attackers to cause a Denial of Service (DoS) or execute arbitrary code via a crafted payload.
- risk 0.64cvss 9.8epss 0.01
Prestashop cdesigner v3.1.3 to v3.1.8 was discovered to contain a code injection vulnerability via the component CdesignerSaverotateModuleFrontController::initContent().
- risk 0.57cvss 9.8epss 0.03
Improper Control of Generation of Code ('Code Injection') vulnerability in Apache Software Foundation Apache Airflow Hive Provider.This issue affects Apache Airflow Hive Provider: before 6.0.0.
- risk 0.64cvss 9.8epss 0.02
BiblioCraft before 2.4.6 does not sanitize path-traversal characters in filenames, allowing restricted write access to almost anywhere on the filesystem. This includes the Minecraft mods folder, which results in code execution.
- risk 0.64cvss 9.8epss 0.02
TOTOlink A7100RU V7.4cu.2313_B20191024 was discovered to contain a command injection vulnerability via the pppoeAcName parameter at /setting/setWanIeCfg.
- risk 0.64cvss 9.8epss 0.02
TOTOlink A7100RU(V7.4cu.2313_B20191024) was discovered to contain a command injection vulnerability via the org parameter at setting/delStaticDhcpRules.
- risk 0.64cvss 9.8epss 0.01
Tenda AC10 US_AC10V4.0si_V16.03.10.13_cn was discovered to contain a stack overflow via the formSetFirewallCfg function. This vulnerability allows attackers to cause a Denial of Service (DoS) or execute arbitrary code via a crafted payload.
- risk 0.64cvss 9.8epss 0.01
Tenda AC10 US_AC10V4.0si_V16.03.10.13_cn was discovered to contain a stack overflow via the saveParentControlInfo function. This vulnerability allows attackers to cause a Denial of Service (DoS) or execute arbitrary code via a crafted payload.
- risk 0.64cvss 9.8epss 0.01
Tenda AC10 US_AC10V4.0si_V16.03.10.13_cn was discovered to contain a stack overflow via the sub_458FBC function. This vulnerability allows attackers to cause a Denial of Service (DoS) or execute arbitrary code via a crafted payload.
- risk 0.64cvss 9.8epss 0.01
Tenda AC10 US_AC10V4.0si_V16.03.10.13_cn was discovered to contain a stack overflow via the sub_45EC1C function. This vulnerability allows attackers to cause a Denial of Service (DoS) or execute arbitrary code via a crafted payload.
- risk 0.64cvss 9.8epss 0.01
Tenda AC10 US_AC10V4.0si_V16.03.10.13_cn was discovered to contain a stack overflow via the sub_45DC58 function. This vulnerability allows attackers to cause a Denial of Service (DoS) or execute arbitrary code via a crafted payload.
- risk 0.64cvss 9.8epss 0.01
Tenda AC10 US_AC10V4.0si_V16.03.10.13_cn was discovered to contain a stack overflow via the R7WebsSecurityHandler function. This vulnerability allows attackers to cause a Denial of Service (DoS) or execute arbitrary code via a crafted payload.
- risk 0.64cvss 9.8epss 0.01
Tenda AC10 US_AC10V4.0si_V16.03.10.13_cn was discovered to contain a stack overflow via the sub_4A75C0 function. This vulnerability allows attackers to cause a Denial of Service (DoS) or execute arbitrary code via a crafted payload.
- risk 0.64cvss 9.8epss 0.01
Tenda AC10 US_AC10V4.0si_V16.03.10.13_cn was discovered to contain a stack overflow via the sub_46AC38 function. This vulnerability allows attackers to cause a Denial of Service (DoS) or execute arbitrary code via a crafted payload.
- risk 0.64cvss 9.8epss 0.01
Tenda AC10 US_AC10V4.0si_V16.03.10.13_cn was discovered to contain a stack overflow via the get_parentControl_list_Info function. This vulnerability allows attackers to cause a Denial of Service (DoS) or execute arbitrary code via a crafted payload.
- risk 0.64cvss 9.8epss 0.01
Tenda AC10 US_AC10V4.0si_V16.03.10.13_cn was discovered to contain a stack overflow via the setSchedWifi function. This vulnerability allows attackers to cause a Denial of Service (DoS) or execute arbitrary code via a crafted payload.
- risk 0.64cvss 9.8epss 0.01
Tenda AC5 US_AC5V1.0RTL_V15.03.06.28 was discovered to contain a stack overflow via the add_white_node function. This vulnerability allows attackers to cause a Denial of Service (DoS) or execute arbitrary code via a crafted payload.