| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-46599 | Cri | 0.64 | 9.8 | 0.01 | Dec 30, 2022 | TRENDnet TEW755AP 1.13B01 was discovered to contain a stack overflow via the setlogo_num parameter in the icp_setlogo_img (sub_41DBF4) function. | ||
| CVE-2022-46598 | Cri | 0.64 | 9.8 | 0.02 | Dec 30, 2022 | TRENDnet TEW755AP 1.13B01 was discovered to contain a command injection vulnerability via the wps_sta_enrollee_pin parameter in the action set_sta_enrollee_pin_5g function. | ||
| CVE-2022-46597 | Cri | 0.64 | 9.8 | 0.02 | Dec 30, 2022 | TRENDnet TEW755AP 1.13B01 was discovered to contain a command injection vulnerability via the sys_service parameter in the setup_wizard_mydlink (sub_4104B8) function. | ||
| CVE-2022-46596 | Cri | 0.64 | 9.8 | 0.01 | Dec 30, 2022 | TRENDnet TEW755AP 1.13B01 was discovered to contain a stack overflow via the del_num parameter in the icp_delete_img (sub_41DEDC) function. | ||
| CVE-2022-46594 | Cri | 0.64 | 9.8 | 0.01 | Dec 30, 2022 | TRENDnet TEW755AP 1.13B01 was discovered to contain a stack overflow via the update_file_name parameter in the auto_up_fw (sub_420A04) function. | ||
| CVE-2022-46593 | Cri | 0.64 | 9.8 | 0.01 | Dec 30, 2022 | TRENDnet TEW755AP 1.13B01 was discovered to contain a stack overflow via the wps_sta_enrollee_pin parameter in the do_sta_enrollee_wifi function. | ||
| CVE-2022-46592 | Cri | 0.64 | 9.8 | 0.01 | Dec 30, 2022 | TRENDnet TEW755AP 1.13B01 was discovered to contain a stack overflow via the wps_sta_enrollee_pin parameter in the set_sta_enrollee_pin_5g function. | ||
| CVE-2022-46591 | Cri | 0.64 | 9.8 | 0.01 | Dec 30, 2022 | TRENDnet TEW755AP 1.13B01 was discovered to contain a stack overflow via the reject_url parameter in the reject (sub_41BD60) function. | ||
| CVE-2022-46590 | Cri | 0.64 | 9.8 | 0.01 | Dec 30, 2022 | TRENDnet TEW755AP 1.13B01 was discovered to contain a stack overflow via the cameo.cameo.netstat_rsname parameter in the tools_netstat (sub_41E730) function. | ||
| CVE-2022-46589 | Cri | 0.64 | 9.8 | 0.01 | Dec 30, 2022 | TRENDnet TEW755AP 1.13B01 was discovered to contain a stack overflow via the cameo.cameo.netstat_option parameter in the tools_netstat (sub_41E730) function. | ||
| CVE-2022-46588 | Cri | 0.64 | 9.8 | 0.01 | Dec 30, 2022 | TRENDnet TEW755AP 1.13B01 was discovered to contain a stack overflow via the sys_service parameter in the setup_wizard_mydlink (sub_4104B8) function. | ||
| CVE-2022-46586 | Cri | 0.64 | 9.8 | 0.01 | Dec 30, 2022 | TRENDnet TEW755AP 1.13B01 was discovered to contain a stack overflow via the qcawifi.wifi%d_vap%d.maclist parameter in the kick_ban_wifi_mac_allow (sub_415B00) function. | ||
| CVE-2022-46585 | Cri | 0.64 | 9.8 | 0.01 | Dec 30, 2022 | TRENDnet TEW755AP 1.13B01 was discovered to contain a stack overflow via the REMOTE_USER parameter in the get_access (sub_45AC2C) function. | ||
| CVE-2022-46584 | Cri | 0.64 | 9.8 | 0.01 | Dec 30, 2022 | TRENDnet TEW755AP 1.13B01 was discovered to contain a stack overflow via the qcawifi.wifi%d_vap%d.maclist parameter in the kick_ban_wifi_mac_deny (sub_415D7C) function. | ||
| CVE-2022-46583 | Cri | 0.64 | 9.8 | 0.01 | Dec 30, 2022 | TRENDnet TEW755AP 1.13B01 was discovered to contain a stack overflow via the reboot_type parameter in the wizard_ipv6 (sub_41C380) function. | ||
| CVE-2022-46582 | Cri | 0.64 | 9.8 | 0.01 | Dec 30, 2022 | TRENDnet TEW755AP 1.13B01 was discovered to contain a stack overflow via the login_name parameter in the do_graph_auth (sub_4061E0) function. | ||
| CVE-2022-46581 | Cri | 0.64 | 9.8 | 0.01 | Dec 30, 2022 | TRENDnet TEW755AP 1.13B01 was discovered to contain a stack overflow via the cameo.cameo.nslookup_target parameter in the tools_nslookup function. | ||
| CVE-2022-46580 | Cri | 0.64 | 9.8 | 0.01 | Dec 30, 2022 | TRENDnet TEW755AP 1.13B01 was discovered to contain a stack overflow via the user_edit_page parameter in the wifi_captive_portal function. | ||
| CVE-2022-44621 | — | Cri | 0.57 | 9.8 | 0.03 | Dec 30, 2022 | Diagnosis Controller miss parameter validation, so user may attacked by command injection via HTTP Request. | |
| CVE-2022-36437 | Cri | 0.59 | 9.1 | 0.01 | Dec 29, 2022 | The Connection handler in Hazelcast and Hazelcast Jet allows a remote unauthenticated attacker to access and manipulate data in the cluster with the identity of another already authenticated connection. The affected Hazelcast versions are through 4.0.6, 4.1.9, 4.2.5, 5.0.3, and… | ||
| CVE-2022-46179 | Cri | 0.00 | 9.2 | 0.00 | Dec 28, 2022 | LiuOS is a small Python project meant to imitate the functions of a regular operating system. Version 0.1.0 and prior of LiuOS allow an attacker to set the GITHUB_ACTIONS environment variable to anything other than null or true and skip authentication checks. This issue is… | ||
| CVE-2022-23555 | Cri | 0.61 | 9.4 | 0.01 | Dec 28, 2022 | authentik is an open-source Identity Provider focused on flexibility and versatility. Versions prior to 2022.11.4 and 2022.10.4 are vulnerable to Improper Authentication. Token reuse in invitation URLs leads to access control bypass via the use of a different enrollment flow… | ||
| CVE-2022-46442 | Cri | 0.64 | 9.8 | 0.01 | Dec 27, 2022 | dedecms <=V5.7.102 is vulnerable to SQL Injection. In sys_ sql_ n query.php there are no restrictions on the sql query. | ||
| CVE-2022-45963 | — | Cri | 0.64 | 9.8 | 0.01 | Dec 27, 2022 | h3c firewall <= 3.10 ESS6703 has a privilege bypass vulnerability. | |
| CVE-2022-45778 | Cri | 0.64 | 9.8 | 0.01 | Dec 27, 2022 | https://www.hillstonenet.com.cn/ Hillstone Firewall SG-6000 <= 5.0.4.0 is vulnerable to Incorrect Access Control. There is a permission bypass vulnerability in the Hillstone WEB application firewall. An attacker can enter the background of the firewall with super administrator… | ||
| CVE-2021-4238 | — | Cri | 0.52 | 9.1 | 0.01 | Dec 27, 2022 | Randomly-generated alphanumeric strings contain significantly less entropy than expected. The RandomAlphaNumeric and CryptoRandomAlphaNumeric functions always return strings containing at least one digit from 0 to 9. This significantly reduces the amount of entropy in short… | |
| CVE-2021-4236 | — | Cri | 0.57 | 9.8 | 0.01 | Dec 27, 2022 | Web Sockets do not execute any AuthenticateMethod methods which may be set, leading to a nil pointer dereference if the returned UserData pointer is assumed to be non-nil, or authentication bypass. This issue only affects WebSockets with an AuthenticateMethod hook. Request… | |
| CVE-2020-36569 | — | Cri | 0.52 | 9.1 | 0.01 | Dec 27, 2022 | Authentication is globally bypassed in github.com/nanobox-io/golang-nanoauth between v0.0.0-20160722212129-ac0cc4484ad4 and v0.0.0-20200131131040-063a3fb69896 if ListenAndServe is called with an empty token. | |
| CVE-2020-36566 | Cri | 0.52 | 9.1 | 0.01 | Dec 27, 2022 | Due to improper path sanitization, archives containing relative file paths can cause files to be written (or overwritten) outside of the target directory. | ||
| CVE-2020-36561 | — | Cri | 0.52 | 9.1 | 0.01 | Dec 27, 2022 | Due to improper path sanitization, archives containing relative file paths can cause files to be written (or overwritten) outside of the target directory. | |
| CVE-2020-36560 | — | Cri | 0.52 | 9.1 | 0.01 | Dec 27, 2022 | Due to improper path sanitization, archives containing relative file paths can cause files to be written (or overwritten) outside of the target directory. | |
| CVE-2018-25046 | — | Cri | 0.52 | 9.1 | 0.01 | Dec 27, 2022 | Due to improper path sanitization, archives containing relative file paths can cause files to be written (or overwritten) outside of the target directory. | |
| CVE-2017-20146 | Cri | 0.57 | 9.8 | 0.01 | Dec 27, 2022 | Usage of the CORS handler may apply improper CORS headers, allowing the requester to explicitly control the value of the Access-Control-Allow-Origin header, which bypasses the expected behavior of the Same Origin Policy. | ||
| CVE-2014-125026 | Cri | 0.57 | 9.8 | 0.01 | Dec 27, 2022 | LZ4 bindings use a deprecated C API that is vulnerable to memory corruption, which could lead to arbitrary code execution if called with untrusted user input. | ||
| CVE-2022-4724 | — | Cri | 0.57 | 9.8 | 0.01 | Dec 27, 2022 | Improper Access Control in GitHub repository ikus060/rdiffweb prior to 2.5.5. | |
| CVE-2022-4719 | — | Cri | 0.57 | 9.8 | 0.01 | Dec 27, 2022 | Business Logic Errors in GitHub repository ikus060/rdiffweb prior to 2.5.5. | |
| CVE-2022-46764 | Cri | 0.64 | 9.8 | 0.02 | Dec 27, 2022 | A SQL injection issue in the web API in TrueConf Server 5.2.0.10225 (fixed in 5.2.6.10025) allows remote unauthenticated attackers to execute arbitrary SQL commands, ultimately leading to remote code execution. | ||
| CVE-2020-24600 | Cri | 0.64 | 9.8 | 0.01 | Dec 26, 2022 | Shilpi CAPExWeb 1.1 allows SQL injection via a servlet/capexweb.cap_sendMail GET request. | ||
| CVE-2019-11851 | Cri | 0.64 | 9.8 | 0.02 | Dec 26, 2022 | The ACENet service in Sierra Wireless ALEOS before 4.4.9, 4.5.x through 4.9.x before 4.9.5, and 4.10.x through 4.13.x before 4.14.0 allows remote attackers to execute arbitrary code via a buffer overflow. | ||
| CVE-2020-11101 | Cri | 0.64 | 9.8 | 0.01 | Dec 26, 2022 | Sierra Wireless AirLink Mobility Manager (AMM) before 2.17 mishandles sessions and thus an unauthenticated attacker can obtain a login session with administrator privileges. | ||
| CVE-2022-4120 | Cri | 0.65 | 9.8 | 0.18 | Dec 26, 2022 | The Stop Spammers Security | Block Spam Users, Comments, Forms WordPress plugin before 2022.6 passes base64 encoded user input to the unserialize() PHP function when CAPTCHA are used as second challenge, which could lead to PHP Object injection if a plugin installed on the blog… | ||
| CVE-2022-4117 | Cri | 0.64 | 9.8 | 0.05 | Dec 26, 2022 | The IWS WordPress plugin through 1.0 does not properly escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to an unauthenticated SQL injection. | ||
| CVE-2022-4047 | Cri | 0.64 | 9.8 | 0.06 | Dec 26, 2022 | The Return Refund and Exchange For WooCommerce WordPress plugin before 4.0.9 does not validate attachment files to be uploaded via an AJAX action available to unauthenticated users, which could allow them to upload arbitrary files such as PHP and lead to RCE | ||
| CVE-2022-26969 | Cri | 0.57 | 9.8 | 0.01 | Dec 26, 2022 | In Directus before 9.7.0, the default settings of CORS_ORIGIN and CORS_ENABLED are true. | ||
| CVE-2022-24119 | Cri | 0.64 | 9.8 | 0.01 | Dec 26, 2022 | Certain General Electric Renewable Energy products have a hidden feature for unauthenticated remote access to the device configuration shell. This affects iNET and iNET II before 8.3.0. | ||
| CVE-2022-24118 | Cri | 0.59 | 9.1 | 0.01 | Dec 26, 2022 | Certain General Electric Renewable Energy products allow attackers to use a code to trigger a reboot into the factory default configuration. This affects iNET and iNET II before 8.3.0, SD before 6.4.7, TD220X before 2.0.16, and TD220MAX before 1.2.6. | ||
| CVE-2022-24117 | Cri | 0.64 | 9.8 | 0.00 | Dec 26, 2022 | Certain General Electric Renewable Energy products download firmware without an integrity check. This affects iNET and iNET II before 8.3.0, SD before 6.4.7, TD220X before 2.0.16, and TD220MAX before 1.2.6. | ||
| CVE-2022-24116 | Cri | 0.64 | 9.8 | 0.00 | Dec 26, 2022 | Certain General Electric Renewable Energy products have inadequate encryption strength. This affects iNET and iNET II before 8.3.0. | ||
| CVE-2021-45467 | Cri | 0.69 | 9.8 | 0.71 | Dec 26, 2022 | In CWP (aka Control Web Panel or CentOS Web Panel) before 0.9.8.1107, an unauthenticated attacker can use %00 bytes to cause /user/loader.php to register an arbitrary API key, as demonstrated by a /user/loader.php?api=1&scripts= .%00./.%00./api/account_new_create&acc=guadaapi… | ||
| CVE-2021-45466 | Cri | 0.68 | 9.8 | 0.55 | Dec 26, 2022 | In CWP (aka Control Web Panel or CentOS Web Panel) before 0.9.8.1107, attackers can make a crafted request to api/?api=add_server&DHCP= to add an authorized_keys text file in the /resources/ folder. |
- risk 0.64cvss 9.8epss 0.01
TRENDnet TEW755AP 1.13B01 was discovered to contain a stack overflow via the setlogo_num parameter in the icp_setlogo_img (sub_41DBF4) function.
- risk 0.64cvss 9.8epss 0.02
TRENDnet TEW755AP 1.13B01 was discovered to contain a command injection vulnerability via the wps_sta_enrollee_pin parameter in the action set_sta_enrollee_pin_5g function.
- risk 0.64cvss 9.8epss 0.02
TRENDnet TEW755AP 1.13B01 was discovered to contain a command injection vulnerability via the sys_service parameter in the setup_wizard_mydlink (sub_4104B8) function.
- risk 0.64cvss 9.8epss 0.01
TRENDnet TEW755AP 1.13B01 was discovered to contain a stack overflow via the del_num parameter in the icp_delete_img (sub_41DEDC) function.
- risk 0.64cvss 9.8epss 0.01
TRENDnet TEW755AP 1.13B01 was discovered to contain a stack overflow via the update_file_name parameter in the auto_up_fw (sub_420A04) function.
- risk 0.64cvss 9.8epss 0.01
TRENDnet TEW755AP 1.13B01 was discovered to contain a stack overflow via the wps_sta_enrollee_pin parameter in the do_sta_enrollee_wifi function.
- risk 0.64cvss 9.8epss 0.01
TRENDnet TEW755AP 1.13B01 was discovered to contain a stack overflow via the wps_sta_enrollee_pin parameter in the set_sta_enrollee_pin_5g function.
- risk 0.64cvss 9.8epss 0.01
TRENDnet TEW755AP 1.13B01 was discovered to contain a stack overflow via the reject_url parameter in the reject (sub_41BD60) function.
- risk 0.64cvss 9.8epss 0.01
TRENDnet TEW755AP 1.13B01 was discovered to contain a stack overflow via the cameo.cameo.netstat_rsname parameter in the tools_netstat (sub_41E730) function.
- risk 0.64cvss 9.8epss 0.01
TRENDnet TEW755AP 1.13B01 was discovered to contain a stack overflow via the cameo.cameo.netstat_option parameter in the tools_netstat (sub_41E730) function.
- risk 0.64cvss 9.8epss 0.01
TRENDnet TEW755AP 1.13B01 was discovered to contain a stack overflow via the sys_service parameter in the setup_wizard_mydlink (sub_4104B8) function.
- risk 0.64cvss 9.8epss 0.01
TRENDnet TEW755AP 1.13B01 was discovered to contain a stack overflow via the qcawifi.wifi%d_vap%d.maclist parameter in the kick_ban_wifi_mac_allow (sub_415B00) function.
- risk 0.64cvss 9.8epss 0.01
TRENDnet TEW755AP 1.13B01 was discovered to contain a stack overflow via the REMOTE_USER parameter in the get_access (sub_45AC2C) function.
- risk 0.64cvss 9.8epss 0.01
TRENDnet TEW755AP 1.13B01 was discovered to contain a stack overflow via the qcawifi.wifi%d_vap%d.maclist parameter in the kick_ban_wifi_mac_deny (sub_415D7C) function.
- risk 0.64cvss 9.8epss 0.01
TRENDnet TEW755AP 1.13B01 was discovered to contain a stack overflow via the reboot_type parameter in the wizard_ipv6 (sub_41C380) function.
- risk 0.64cvss 9.8epss 0.01
TRENDnet TEW755AP 1.13B01 was discovered to contain a stack overflow via the login_name parameter in the do_graph_auth (sub_4061E0) function.
- risk 0.64cvss 9.8epss 0.01
TRENDnet TEW755AP 1.13B01 was discovered to contain a stack overflow via the cameo.cameo.nslookup_target parameter in the tools_nslookup function.
- risk 0.64cvss 9.8epss 0.01
TRENDnet TEW755AP 1.13B01 was discovered to contain a stack overflow via the user_edit_page parameter in the wifi_captive_portal function.
- risk 0.57cvss 9.8epss 0.03
Diagnosis Controller miss parameter validation, so user may attacked by command injection via HTTP Request.
- risk 0.59cvss 9.1epss 0.01
The Connection handler in Hazelcast and Hazelcast Jet allows a remote unauthenticated attacker to access and manipulate data in the cluster with the identity of another already authenticated connection. The affected Hazelcast versions are through 4.0.6, 4.1.9, 4.2.5, 5.0.3, and…
- risk 0.00cvss 9.2epss 0.00
LiuOS is a small Python project meant to imitate the functions of a regular operating system. Version 0.1.0 and prior of LiuOS allow an attacker to set the GITHUB_ACTIONS environment variable to anything other than null or true and skip authentication checks. This issue is…
- risk 0.61cvss 9.4epss 0.01
authentik is an open-source Identity Provider focused on flexibility and versatility. Versions prior to 2022.11.4 and 2022.10.4 are vulnerable to Improper Authentication. Token reuse in invitation URLs leads to access control bypass via the use of a different enrollment flow…
- risk 0.64cvss 9.8epss 0.01
dedecms <=V5.7.102 is vulnerable to SQL Injection. In sys_ sql_ n query.php there are no restrictions on the sql query.
- risk 0.64cvss 9.8epss 0.01
h3c firewall <= 3.10 ESS6703 has a privilege bypass vulnerability.
- risk 0.64cvss 9.8epss 0.01
https://www.hillstonenet.com.cn/ Hillstone Firewall SG-6000 <= 5.0.4.0 is vulnerable to Incorrect Access Control. There is a permission bypass vulnerability in the Hillstone WEB application firewall. An attacker can enter the background of the firewall with super administrator…
- risk 0.52cvss 9.1epss 0.01
Randomly-generated alphanumeric strings contain significantly less entropy than expected. The RandomAlphaNumeric and CryptoRandomAlphaNumeric functions always return strings containing at least one digit from 0 to 9. This significantly reduces the amount of entropy in short…
- risk 0.57cvss 9.8epss 0.01
Web Sockets do not execute any AuthenticateMethod methods which may be set, leading to a nil pointer dereference if the returned UserData pointer is assumed to be non-nil, or authentication bypass. This issue only affects WebSockets with an AuthenticateMethod hook. Request…
- risk 0.52cvss 9.1epss 0.01
Authentication is globally bypassed in github.com/nanobox-io/golang-nanoauth between v0.0.0-20160722212129-ac0cc4484ad4 and v0.0.0-20200131131040-063a3fb69896 if ListenAndServe is called with an empty token.
- risk 0.52cvss 9.1epss 0.01
Due to improper path sanitization, archives containing relative file paths can cause files to be written (or overwritten) outside of the target directory.
- risk 0.52cvss 9.1epss 0.01
Due to improper path sanitization, archives containing relative file paths can cause files to be written (or overwritten) outside of the target directory.
- risk 0.52cvss 9.1epss 0.01
Due to improper path sanitization, archives containing relative file paths can cause files to be written (or overwritten) outside of the target directory.
- risk 0.52cvss 9.1epss 0.01
Due to improper path sanitization, archives containing relative file paths can cause files to be written (or overwritten) outside of the target directory.
- risk 0.57cvss 9.8epss 0.01
Usage of the CORS handler may apply improper CORS headers, allowing the requester to explicitly control the value of the Access-Control-Allow-Origin header, which bypasses the expected behavior of the Same Origin Policy.
- risk 0.57cvss 9.8epss 0.01
LZ4 bindings use a deprecated C API that is vulnerable to memory corruption, which could lead to arbitrary code execution if called with untrusted user input.
- risk 0.57cvss 9.8epss 0.01
Improper Access Control in GitHub repository ikus060/rdiffweb prior to 2.5.5.
- risk 0.57cvss 9.8epss 0.01
Business Logic Errors in GitHub repository ikus060/rdiffweb prior to 2.5.5.
- risk 0.64cvss 9.8epss 0.02
A SQL injection issue in the web API in TrueConf Server 5.2.0.10225 (fixed in 5.2.6.10025) allows remote unauthenticated attackers to execute arbitrary SQL commands, ultimately leading to remote code execution.
- risk 0.64cvss 9.8epss 0.01
Shilpi CAPExWeb 1.1 allows SQL injection via a servlet/capexweb.cap_sendMail GET request.
- risk 0.64cvss 9.8epss 0.02
The ACENet service in Sierra Wireless ALEOS before 4.4.9, 4.5.x through 4.9.x before 4.9.5, and 4.10.x through 4.13.x before 4.14.0 allows remote attackers to execute arbitrary code via a buffer overflow.
- risk 0.64cvss 9.8epss 0.01
Sierra Wireless AirLink Mobility Manager (AMM) before 2.17 mishandles sessions and thus an unauthenticated attacker can obtain a login session with administrator privileges.
- risk 0.65cvss 9.8epss 0.18
The Stop Spammers Security | Block Spam Users, Comments, Forms WordPress plugin before 2022.6 passes base64 encoded user input to the unserialize() PHP function when CAPTCHA are used as second challenge, which could lead to PHP Object injection if a plugin installed on the blog…
- risk 0.64cvss 9.8epss 0.05
The IWS WordPress plugin through 1.0 does not properly escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to an unauthenticated SQL injection.
- risk 0.64cvss 9.8epss 0.06
The Return Refund and Exchange For WooCommerce WordPress plugin before 4.0.9 does not validate attachment files to be uploaded via an AJAX action available to unauthenticated users, which could allow them to upload arbitrary files such as PHP and lead to RCE
- risk 0.57cvss 9.8epss 0.01
In Directus before 9.7.0, the default settings of CORS_ORIGIN and CORS_ENABLED are true.
- risk 0.64cvss 9.8epss 0.01
Certain General Electric Renewable Energy products have a hidden feature for unauthenticated remote access to the device configuration shell. This affects iNET and iNET II before 8.3.0.
- risk 0.59cvss 9.1epss 0.01
Certain General Electric Renewable Energy products allow attackers to use a code to trigger a reboot into the factory default configuration. This affects iNET and iNET II before 8.3.0, SD before 6.4.7, TD220X before 2.0.16, and TD220MAX before 1.2.6.
- risk 0.64cvss 9.8epss 0.00
Certain General Electric Renewable Energy products download firmware without an integrity check. This affects iNET and iNET II before 8.3.0, SD before 6.4.7, TD220X before 2.0.16, and TD220MAX before 1.2.6.
- risk 0.64cvss 9.8epss 0.00
Certain General Electric Renewable Energy products have inadequate encryption strength. This affects iNET and iNET II before 8.3.0.
- risk 0.69cvss 9.8epss 0.71
In CWP (aka Control Web Panel or CentOS Web Panel) before 0.9.8.1107, an unauthenticated attacker can use %00 bytes to cause /user/loader.php to register an arbitrary API key, as demonstrated by a /user/loader.php?api=1&scripts= .%00./.%00./api/account_new_create&acc=guadaapi…
- risk 0.68cvss 9.8epss 0.55
In CWP (aka Control Web Panel or CentOS Web Panel) before 0.9.8.1107, attackers can make a crafted request to api/?api=add_server&DHCP= to add an authorized_keys text file in the /resources/ folder.