VYPR

Satcom Sailor 250 and 500

by Cobham

CVEs (2)

  • CVE-2018-19392CriMar 15, 2019
    risk 0.64cvss 9.8epss 0.01

    Cobham Satcom Sailor 250 and 500 devices before 1.25 contained an unauthenticated password reset vulnerability. This could allow modification of any user account's password (including the default "admin" account), without prior knowledge of their password. All that is required…

  • CVE-2018-19391MedMar 15, 2019
    risk 0.40cvss 6.1epss 0.01

    Cobham Satcom Sailor 250 and 500 devices before 1.25 contained persistent XSS, which could be exploited by an unauthenticated threat actor via the /index.lua?pageID=Phone%20book name field.