Goodcloud
by Gl Inet
CVEs (4)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-44211 | Hig | 0.48 | 7.4 | 0.01 | Dec 1, 2022 | In GL.iNet Goodcloud 1.1 Incorrect access control allows a remote attacker to access/change devices' settings. | ||
| CVE-2022-42055 | Med | 0.42 | 6.5 | 0.02 | Oct 27, 2022 | Multiple command injection vulnerabilities in GL.iNet GoodCloud IoT Device Management System Version 1.00.220412.00 via the ping and traceroute tools allow attackers to read arbitrary files on the system. | ||
| CVE-2022-44212 | Med | 0.38 | 5.9 | 0.01 | Dec 1, 2022 | In GL.iNet Goodcloud 1.0, insecure design allows remote attacker to access devices' admin panel. | ||
| CVE-2022-42054 | Med | 0.35 | 5.4 | 0.00 | Oct 27, 2022 | Multiple stored cross-site scripting (XSS) vulnerabilities in GL.iNet GoodCloud IoT Device Management System Version 1.00.220412.00 allow attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Company Name and Description text fields. |
- risk 0.48cvss 7.4epss 0.01
In GL.iNet Goodcloud 1.1 Incorrect access control allows a remote attacker to access/change devices' settings.
- risk 0.42cvss 6.5epss 0.02
Multiple command injection vulnerabilities in GL.iNet GoodCloud IoT Device Management System Version 1.00.220412.00 via the ping and traceroute tools allow attackers to read arbitrary files on the system.
- risk 0.38cvss 5.9epss 0.01
In GL.iNet Goodcloud 1.0, insecure design allows remote attacker to access devices' admin panel.
- risk 0.35cvss 5.4epss 0.00
Multiple stored cross-site scripting (XSS) vulnerabilities in GL.iNet GoodCloud IoT Device Management System Version 1.00.220412.00 allow attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Company Name and Description text fields.