| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-3616 | Cri | 0.64 | 9.8 | 0.01 | Sep 5, 2023 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Mava Software Hotel Management System allows SQL Injection. This issue affects Hotel Management System: before 2.0. | ||
| CVE-2023-39681 | Cri | 0.64 | 9.8 | 0.02 | Sep 5, 2023 | Cuppa CMS v1.0 was discovered to contain a remote code execution (RCE) vulnerability via the email_outgoing parameter at /Configuration.php. This vulnerability is triggered via a crafted payload. | ||
| CVE-2023-35072 | Cri | 0.64 | 9.8 | 0.01 | Sep 5, 2023 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Coyav Travel Proagent allows SQL Injection. This issue affects Proagent: before 20230904 . | ||
| CVE-2023-35068 | Cri | 0.64 | 9.8 | 0.01 | Sep 5, 2023 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in BMA Personnel Tracking System allows SQL Injection. This issue affects Personnel Tracking System: before 20230904. | ||
| CVE-2023-35065 | Cri | 0.64 | 9.8 | 0.01 | Sep 5, 2023 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Osoft Paint Production Management allows SQL Injection. This issue affects Paint Production Management: before 2.1. | ||
| CVE-2017-9453 | Cri | 0.59 | 9.0 | 0.01 | Sep 5, 2023 | BMC Server Automation before 8.9.01 patch 1 allows Process Spawner command execution because of authentication bypass. | ||
| CVE-2023-3374 | Cri | 0.64 | 9.8 | 0.01 | Sep 5, 2023 | Incomplete List of Disallowed Inputs vulnerability in Unisign Bookreen allows Privilege Escalation. This issue affects Bookreen: before 3.0.0. | ||
| CVE-2023-41012 | Cri | 0.64 | 9.8 | 0.02 | Sep 5, 2023 | An issue in China Mobile Communications China Mobile Intelligent Home Gateway v.HG6543C4 allows a remote attacker to execute arbitrary code via the authentication mechanism. | ||
| CVE-2023-36361 | Cri | 0.64 | 9.8 | 0.01 | Sep 5, 2023 | Audimexee v14.1.7 was discovered to contain a SQL injection vulnerability via the p_table_name parameter. | ||
| CVE-2023-40743 | Cri | 0.57 | 9.8 | 0.03 | Sep 5, 2023 | ** UNSUPPORTED WHEN ASSIGNED ** When integrating Apache Axis 1.x in an application, it may not have been obvious that looking up a service through "ServiceFactory.getService" allows potentially dangerous lookup mechanisms such as LDAP. When passing untrusted input to this API… | ||
| CVE-2023-41910 | Cri | 0.00 | 9.8 | 0.01 | Sep 5, 2023 | An issue was discovered in lldpd before 1.0.17. By crafting a CDP PDU packet with specific CDP_TLV_ADDRESSES TLVs, a malicious actor can remotely force the lldpd daemon to perform an out-of-bounds read on heap memory. This occurs in cdp_decode in daemon/protocols/cdp.c. | ||
| CVE-2023-28581 | Cri | 0.64 | 9.8 | 0.01 | Sep 5, 2023 | Memory corruption in WLAN Firmware while parsing receieved GTK Keys in GTK KDE. | ||
| CVE-2023-28562 | Cri | 0.64 | 9.8 | 0.00 | Sep 5, 2023 | Memory corruption while handling payloads from remote ESL. | ||
| CVE-2023-4614 | Cri | 0.64 | 9.8 | 0.03 | Sep 4, 2023 | This vulnerability allows remote attackers to execute arbitrary code on affected installations of LG LED Assistant. Authentication is not required to exploit this vulnerability. The specific flaw exists within the /api/installation/setThumbnailRc endpoint. The issue results from… | ||
| CVE-2023-4613 | Cri | 0.64 | 9.8 | 0.03 | Sep 4, 2023 | This vulnerability allows remote attackers to execute arbitrary code on affected installations of LG LED Assistant. Authentication is not required to exploit this vulnerability. The specific flaw exists within the /api/settings/upload endpoint. The issue results from the lack of… | ||
| CVE-2023-4744 | Cri | 0.64 | 9.8 | 0.02 | Sep 4, 2023 | A vulnerability was found in Tenda AC8 16.03.34.06_cn_TDC01. It has been declared as critical. Affected by this vulnerability is the function formSetDeviceName. The manipulation leads to stack-based buffer overflow. The attack can be launched remotely. The exploit has been… | ||
| CVE-2023-3703 | Cri | 0.65 | 10.0 | 0.01 | Sep 3, 2023 | Proscend Advice ICR Series routers FW version 1.76 - CWE-1392: Use of Default Credentials | ||
| CVE-2023-39979 | Cri | 0.64 | 9.8 | 0.01 | Sep 2, 2023 | There is a vulnerability in MXsecurity versions prior to 1.0.1 that can be exploited to bypass authentication. A remote attacker might access the system if the web service authenticator has insufficient random values. | ||
| CVE-2023-1523 | Cri | 0.00 | 10.0 | 0.01 | Sep 1, 2023 | Using the TIOCLINUX ioctl request, a malicious snap could inject contents into the input of the controlling terminal which could allow it to cause arbitrary commands to be executed outside of the snap sandbox after the snap exits. Graphical terminal emulators like xterm,… | ||
| CVE-2023-40980 | Cri | 0.64 | 9.8 | 0.01 | Sep 1, 2023 | File Upload vulnerability in DWSurvey DWSurvey-OSS v.3.2.0 and before allows a remote attacker to execute arbitrary code via the saveimage method and savveFile in the action/UploadAction.java file. | ||
| CVE-2023-39631 | Cri | 0.57 | 9.8 | 0.02 | Sep 1, 2023 | An issue in LanChain-ai Langchain v.0.0.245 allows a remote attacker to execute arbitrary code via the evaluate function in the numexpr library. | ||
| CVE-2023-36328 | Cri | 0.00 | 9.8 | 0.01 | Sep 1, 2023 | Integer Overflow vulnerability in mp_grow in libtom libtommath before commit beba892bc0d4e4ded4d667ab1d2a94f4d75109a9, allows attackers to execute arbitrary code and cause a denial of service (DoS). | ||
| CVE-2023-36327 | Cri | 0.00 | 9.8 | 0.01 | Sep 1, 2023 | Integer Overflow vulnerability in RELIC before commit 421f2e91cf2ba42473d4d54daf24e295679e290e, allows attackers to execute arbitrary code and cause a denial of service in pos argument in bn_get_prime function. | ||
| CVE-2023-36326 | Cri | 0.00 | 9.8 | 0.01 | Sep 1, 2023 | Integer Overflow vulnerability in RELIC before commit 34580d840469361ba9b5f001361cad659687b9ab, allows attackers to execute arbitrary code, cause a denial of service, and escalate privileges when calling realloc function in bn_grow function. | ||
| CVE-2023-36187 | Cri | 0.64 | 9.8 | 0.01 | Sep 1, 2023 | Buffer Overflow vulnerability in NETGEAR R6400v2 before version 1.0.4.118, allows remote unauthenticated attackers to execute arbitrary code via crafted URL to httpd. | ||
| CVE-2023-36100 | Cri | 0.64 | 9.8 | 0.01 | Sep 1, 2023 | An issue was discovered in IceCMS version 2.0.1, allows attackers to escalate privileges and gain sensitive information via UserID parameter in api/User/ChangeUser. | ||
| CVE-2023-36076 | Cri | 0.64 | 9.8 | 0.03 | Sep 1, 2023 | SQL Injection vulnerability in smanga version 3.1.9 and earlier, allows remote attackers to execute arbitrary code and gain sensitive information via mediaId, mangaId, and userId parameters in php/history/add.php. | ||
| CVE-2020-22612 | Cri | 0.64 | 9.8 | 0.01 | Sep 1, 2023 | Installer RCE on settings file write in MyBB before 1.8.22. | ||
| CVE-2023-41364 | Cri | 0.64 | 9.8 | 0.01 | Sep 1, 2023 | In tine through 2023.01.14.325, the sort parameter of the /index.php endpoint allows SQL Injection. | ||
| CVE-2023-4696 | Cri | 0.57 | 9.8 | 0.01 | Sep 1, 2023 | Improper Access Control in GitHub repository usememos/memos prior to 0.13.2. | ||
| CVE-2023-4299 | Cri | 0.59 | 9.0 | 0.01 | Aug 31, 2023 | Digi RealPort Protocol is vulnerable to a replay attack that may allow an attacker to bypass authentication to access connected equipment. | ||
| CVE-2023-41748 | Cri | 0.64 | 9.8 | 0.01 | Aug 31, 2023 | Remote command execution due to improper input validation. The following products are affected: Acronis Cloud Manager (Windows) before build 6.2.23089.203. | ||
| CVE-2023-41746 | Cri | 0.64 | 9.8 | 0.01 | Aug 31, 2023 | Remote command execution due to improper input validation. The following products are affected: Acronis Cloud Manager (Windows) before build 6.2.23089.203. | ||
| CVE-2023-41637 | Cri | 0.64 | 9.8 | 0.01 | Aug 31, 2023 | An arbitrary file upload vulnerability in the Carica immagine function of GruppoSCAI RealGimm 1.1.37p38 allows attackers to execute arbitrary code via uploading a crafted HTML file. | ||
| CVE-2023-41636 | Cri | 0.64 | 9.8 | 0.01 | Aug 31, 2023 | A SQL injection vulnerability in the Data Richiesta dal parameter of GruppoSCAI RealGimm v1.1.37p38 allows attackers to access the database and execute arbitrary commands via a crafted SQL query. | ||
| CVE-2023-28801 | Cri | 0.62 | 9.6 | 0.00 | Aug 31, 2023 | An Improper Verification of Cryptographic Signature in the SAML authentication of the Zscaler Admin UI allows a Privilege Escalation.This issue affects Admin UI: from 6.2 before 6.2r. | ||
| CVE-2023-3162 | Cri | 0.57 | 9.8 | 0.01 | Aug 31, 2023 | The Stripe Payment Plugin for WooCommerce plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 3.7.7. This is due to insufficient verification on the user being supplied during a Stripe checkout through the plugin. This allows… | ||
| CVE-2023-31714 | Cri | 0.03 | 9.8 | 0.06 | Aug 30, 2023 | Chitor-CMS before v1.1.2 was discovered to contain multiple SQL injection vulnerabilities. | ||
| CVE-2023-40582 | Cri | 0.57 | 9.8 | 0.02 | Aug 30, 2023 | find-exec is a utility to discover available shell commands. Versions prior to 1.0.3 did not properly escape user input and are vulnerable to Command Injection via an attacker controlled parameter. As a result, attackers may run malicious shell commands in the context of the… | ||
| CVE-2023-40848 | Cri | 0.64 | 9.8 | 0.01 | Aug 30, 2023 | Tenda AC6 US_AC6V1.0BR_V15.03.05.16_multi_TD01.bin is vulnerable to Buffer Overflow via the function "sub_7D858." | ||
| CVE-2023-40847 | Cri | 0.64 | 9.8 | 0.01 | Aug 30, 2023 | Tenda AC6 US_AC6V1.0BR_V15.03.05.16_multi_TD01.bin is vulnerable to Buffer Overflow via the function "initIpAddrInfo." In the function, it reads in a user-provided parameter, and the variable is passed to the function without any length check. | ||
| CVE-2023-40845 | Cri | 0.64 | 9.8 | 0.01 | Aug 30, 2023 | Tenda AC6 US_AC6V1.0BR_V15.03.05.16_multi_TD01.bin is vulnerable to Buffer Overflow via function 'sub_34FD0.' In the function, it reads user provided parameters and passes variables to the function without any length checks. | ||
| CVE-2023-40844 | Cri | 0.64 | 9.8 | 0.01 | Aug 30, 2023 | Tenda AC6 US_AC6V1.0BR_V15.03.05.16_multi_TD01.bin is vulnerable to Buffer Overflow via function 'formWifiBasicSet.' | ||
| CVE-2023-40843 | Cri | 0.64 | 9.8 | 0.01 | Aug 30, 2023 | Tenda AC6 US_AC6V1.0BR_V15.03.05.16_multi_TD01.bin is vulnerable to Buffer Overflow via function "sub_73004." | ||
| CVE-2023-40842 | Cri | 0.64 | 9.8 | 0.01 | Aug 30, 2023 | Tengda AC6 US_AC6V1.0BR_V15.03.05.16_multi_TD01.bin is vulnerable to Buffer Overflow via function "R7WebsSecurityHandler." | ||
| CVE-2023-40841 | Cri | 0.64 | 9.8 | 0.01 | Aug 30, 2023 | Tenda AC6 US_AC6V1.0BR_V15.03.05.16_multi_TD01.bin is vulnerable to Buffer Overflow via function "add_white_node," | ||
| CVE-2023-40840 | Cri | 0.64 | 9.8 | 0.01 | Aug 30, 2023 | Tenda AC6 US_AC6V1.0BR_V15.03.05.16_multi_TD01.bin is vulnerable to Buffer Overflow via function "fromGetWirelessRepeat." | ||
| CVE-2023-40839 | Cri | 0.64 | 9.8 | 0.01 | Aug 30, 2023 | Tenda AC6 US_AC6V1.0BR_V15.03.05.16_multi_TD01.bin function 'sub_ADF3C' contains a command execution vulnerability. In the "formSetIptv" function, obtaining the "list" and "vlanId" fields, unfiltered passing these two fields as parameters to the "sub_ADF3C" function to execute… | ||
| CVE-2023-40838 | Cri | 0.64 | 9.8 | 0.01 | Aug 30, 2023 | Tenda AC6 US_AC6V1.0BR_V15.03.05.16_multi_TD01.bin function 'sub_3A1D0' contains a command execution vulnerability. | ||
| CVE-2023-40837 | Cri | 0.64 | 9.8 | 0.01 | Aug 30, 2023 | Tenda AC6 US_AC6V1.0BR_V15.03.05.16_multi_TD01.bin function 'sub_ADD50' contains a command execution vulnerability. In the "formSetIptv" function, obtaining the "list" and "vlanId" fields, unfiltered passing these two fields as parameters to the "sub_ADD50" function to execute… |
- risk 0.64cvss 9.8epss 0.01
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Mava Software Hotel Management System allows SQL Injection. This issue affects Hotel Management System: before 2.0.
- risk 0.64cvss 9.8epss 0.02
Cuppa CMS v1.0 was discovered to contain a remote code execution (RCE) vulnerability via the email_outgoing parameter at /Configuration.php. This vulnerability is triggered via a crafted payload.
- risk 0.64cvss 9.8epss 0.01
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Coyav Travel Proagent allows SQL Injection. This issue affects Proagent: before 20230904 .
- risk 0.64cvss 9.8epss 0.01
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in BMA Personnel Tracking System allows SQL Injection. This issue affects Personnel Tracking System: before 20230904.
- risk 0.64cvss 9.8epss 0.01
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Osoft Paint Production Management allows SQL Injection. This issue affects Paint Production Management: before 2.1.
- risk 0.59cvss 9.0epss 0.01
BMC Server Automation before 8.9.01 patch 1 allows Process Spawner command execution because of authentication bypass.
- risk 0.64cvss 9.8epss 0.01
Incomplete List of Disallowed Inputs vulnerability in Unisign Bookreen allows Privilege Escalation. This issue affects Bookreen: before 3.0.0.
- risk 0.64cvss 9.8epss 0.02
An issue in China Mobile Communications China Mobile Intelligent Home Gateway v.HG6543C4 allows a remote attacker to execute arbitrary code via the authentication mechanism.
- risk 0.64cvss 9.8epss 0.01
Audimexee v14.1.7 was discovered to contain a SQL injection vulnerability via the p_table_name parameter.
- risk 0.57cvss 9.8epss 0.03
** UNSUPPORTED WHEN ASSIGNED ** When integrating Apache Axis 1.x in an application, it may not have been obvious that looking up a service through "ServiceFactory.getService" allows potentially dangerous lookup mechanisms such as LDAP. When passing untrusted input to this API…
- risk 0.00cvss 9.8epss 0.01
An issue was discovered in lldpd before 1.0.17. By crafting a CDP PDU packet with specific CDP_TLV_ADDRESSES TLVs, a malicious actor can remotely force the lldpd daemon to perform an out-of-bounds read on heap memory. This occurs in cdp_decode in daemon/protocols/cdp.c.
- risk 0.64cvss 9.8epss 0.01
Memory corruption in WLAN Firmware while parsing receieved GTK Keys in GTK KDE.
- risk 0.64cvss 9.8epss 0.00
Memory corruption while handling payloads from remote ESL.
- risk 0.64cvss 9.8epss 0.03
This vulnerability allows remote attackers to execute arbitrary code on affected installations of LG LED Assistant. Authentication is not required to exploit this vulnerability. The specific flaw exists within the /api/installation/setThumbnailRc endpoint. The issue results from…
- risk 0.64cvss 9.8epss 0.03
This vulnerability allows remote attackers to execute arbitrary code on affected installations of LG LED Assistant. Authentication is not required to exploit this vulnerability. The specific flaw exists within the /api/settings/upload endpoint. The issue results from the lack of…
- risk 0.64cvss 9.8epss 0.02
A vulnerability was found in Tenda AC8 16.03.34.06_cn_TDC01. It has been declared as critical. Affected by this vulnerability is the function formSetDeviceName. The manipulation leads to stack-based buffer overflow. The attack can be launched remotely. The exploit has been…
- risk 0.65cvss 10.0epss 0.01
Proscend Advice ICR Series routers FW version 1.76 - CWE-1392: Use of Default Credentials
- risk 0.64cvss 9.8epss 0.01
There is a vulnerability in MXsecurity versions prior to 1.0.1 that can be exploited to bypass authentication. A remote attacker might access the system if the web service authenticator has insufficient random values.
- risk 0.00cvss 10.0epss 0.01
Using the TIOCLINUX ioctl request, a malicious snap could inject contents into the input of the controlling terminal which could allow it to cause arbitrary commands to be executed outside of the snap sandbox after the snap exits. Graphical terminal emulators like xterm,…
- risk 0.64cvss 9.8epss 0.01
File Upload vulnerability in DWSurvey DWSurvey-OSS v.3.2.0 and before allows a remote attacker to execute arbitrary code via the saveimage method and savveFile in the action/UploadAction.java file.
- risk 0.57cvss 9.8epss 0.02
An issue in LanChain-ai Langchain v.0.0.245 allows a remote attacker to execute arbitrary code via the evaluate function in the numexpr library.
- risk 0.00cvss 9.8epss 0.01
Integer Overflow vulnerability in mp_grow in libtom libtommath before commit beba892bc0d4e4ded4d667ab1d2a94f4d75109a9, allows attackers to execute arbitrary code and cause a denial of service (DoS).
- risk 0.00cvss 9.8epss 0.01
Integer Overflow vulnerability in RELIC before commit 421f2e91cf2ba42473d4d54daf24e295679e290e, allows attackers to execute arbitrary code and cause a denial of service in pos argument in bn_get_prime function.
- risk 0.00cvss 9.8epss 0.01
Integer Overflow vulnerability in RELIC before commit 34580d840469361ba9b5f001361cad659687b9ab, allows attackers to execute arbitrary code, cause a denial of service, and escalate privileges when calling realloc function in bn_grow function.
- risk 0.64cvss 9.8epss 0.01
Buffer Overflow vulnerability in NETGEAR R6400v2 before version 1.0.4.118, allows remote unauthenticated attackers to execute arbitrary code via crafted URL to httpd.
- risk 0.64cvss 9.8epss 0.01
An issue was discovered in IceCMS version 2.0.1, allows attackers to escalate privileges and gain sensitive information via UserID parameter in api/User/ChangeUser.
- risk 0.64cvss 9.8epss 0.03
SQL Injection vulnerability in smanga version 3.1.9 and earlier, allows remote attackers to execute arbitrary code and gain sensitive information via mediaId, mangaId, and userId parameters in php/history/add.php.
- risk 0.64cvss 9.8epss 0.01
Installer RCE on settings file write in MyBB before 1.8.22.
- risk 0.64cvss 9.8epss 0.01
In tine through 2023.01.14.325, the sort parameter of the /index.php endpoint allows SQL Injection.
- risk 0.57cvss 9.8epss 0.01
Improper Access Control in GitHub repository usememos/memos prior to 0.13.2.
- risk 0.59cvss 9.0epss 0.01
Digi RealPort Protocol is vulnerable to a replay attack that may allow an attacker to bypass authentication to access connected equipment.
- risk 0.64cvss 9.8epss 0.01
Remote command execution due to improper input validation. The following products are affected: Acronis Cloud Manager (Windows) before build 6.2.23089.203.
- risk 0.64cvss 9.8epss 0.01
Remote command execution due to improper input validation. The following products are affected: Acronis Cloud Manager (Windows) before build 6.2.23089.203.
- risk 0.64cvss 9.8epss 0.01
An arbitrary file upload vulnerability in the Carica immagine function of GruppoSCAI RealGimm 1.1.37p38 allows attackers to execute arbitrary code via uploading a crafted HTML file.
- risk 0.64cvss 9.8epss 0.01
A SQL injection vulnerability in the Data Richiesta dal parameter of GruppoSCAI RealGimm v1.1.37p38 allows attackers to access the database and execute arbitrary commands via a crafted SQL query.
- risk 0.62cvss 9.6epss 0.00
An Improper Verification of Cryptographic Signature in the SAML authentication of the Zscaler Admin UI allows a Privilege Escalation.This issue affects Admin UI: from 6.2 before 6.2r.
- risk 0.57cvss 9.8epss 0.01
The Stripe Payment Plugin for WooCommerce plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 3.7.7. This is due to insufficient verification on the user being supplied during a Stripe checkout through the plugin. This allows…
- risk 0.03cvss 9.8epss 0.06
Chitor-CMS before v1.1.2 was discovered to contain multiple SQL injection vulnerabilities.
- risk 0.57cvss 9.8epss 0.02
find-exec is a utility to discover available shell commands. Versions prior to 1.0.3 did not properly escape user input and are vulnerable to Command Injection via an attacker controlled parameter. As a result, attackers may run malicious shell commands in the context of the…
- risk 0.64cvss 9.8epss 0.01
Tenda AC6 US_AC6V1.0BR_V15.03.05.16_multi_TD01.bin is vulnerable to Buffer Overflow via the function "sub_7D858."
- risk 0.64cvss 9.8epss 0.01
Tenda AC6 US_AC6V1.0BR_V15.03.05.16_multi_TD01.bin is vulnerable to Buffer Overflow via the function "initIpAddrInfo." In the function, it reads in a user-provided parameter, and the variable is passed to the function without any length check.
- risk 0.64cvss 9.8epss 0.01
Tenda AC6 US_AC6V1.0BR_V15.03.05.16_multi_TD01.bin is vulnerable to Buffer Overflow via function 'sub_34FD0.' In the function, it reads user provided parameters and passes variables to the function without any length checks.
- risk 0.64cvss 9.8epss 0.01
Tenda AC6 US_AC6V1.0BR_V15.03.05.16_multi_TD01.bin is vulnerable to Buffer Overflow via function 'formWifiBasicSet.'
- risk 0.64cvss 9.8epss 0.01
Tenda AC6 US_AC6V1.0BR_V15.03.05.16_multi_TD01.bin is vulnerable to Buffer Overflow via function "sub_73004."
- risk 0.64cvss 9.8epss 0.01
Tengda AC6 US_AC6V1.0BR_V15.03.05.16_multi_TD01.bin is vulnerable to Buffer Overflow via function "R7WebsSecurityHandler."
- risk 0.64cvss 9.8epss 0.01
Tenda AC6 US_AC6V1.0BR_V15.03.05.16_multi_TD01.bin is vulnerable to Buffer Overflow via function "add_white_node,"
- risk 0.64cvss 9.8epss 0.01
Tenda AC6 US_AC6V1.0BR_V15.03.05.16_multi_TD01.bin is vulnerable to Buffer Overflow via function "fromGetWirelessRepeat."
- risk 0.64cvss 9.8epss 0.01
Tenda AC6 US_AC6V1.0BR_V15.03.05.16_multi_TD01.bin function 'sub_ADF3C' contains a command execution vulnerability. In the "formSetIptv" function, obtaining the "list" and "vlanId" fields, unfiltered passing these two fields as parameters to the "sub_ADF3C" function to execute…
- risk 0.64cvss 9.8epss 0.01
Tenda AC6 US_AC6V1.0BR_V15.03.05.16_multi_TD01.bin function 'sub_3A1D0' contains a command execution vulnerability.
- risk 0.64cvss 9.8epss 0.01
Tenda AC6 US_AC6V1.0BR_V15.03.05.16_multi_TD01.bin function 'sub_ADD50' contains a command execution vulnerability. In the "formSetIptv" function, obtaining the "list" and "vlanId" fields, unfiltered passing these two fields as parameters to the "sub_ADD50" function to execute…