DL4323
by Netis
CVEs (7)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2019-20074 | Hig | 0.57 | 8.8 | 0.01 | Dec 30, 2019 | On Netis DL4323 devices, any user role can view sensitive information, such as a user password or the FTP password, via the form2saveConf.cgi page. | ||
| CVE-2019-20071 | Med | 0.42 | 6.5 | 0.01 | Dec 30, 2019 | On Netis DL4323 devices, CSRF exists via form2logaction.cgi to delete all logs. | ||
| CVE-2019-20076 | Med | 0.40 | 6.1 | 0.02 | Dec 30, 2019 | On Netis DL4323 devices, XSS exists via the form2Ddns.cgi username parameter (DynDns settings of the Dynamic DNS Configuration). | ||
| CVE-2019-20075 | Med | 0.40 | 6.1 | 0.02 | Dec 30, 2019 | On Netis DL4323 devices, pingrtt_v6.html has XSS (Ping6 Diagnostic). | ||
| CVE-2019-20073 | Med | 0.40 | 6.1 | 0.02 | Dec 30, 2019 | On Netis DL4323 devices, XSS exists via the form2userconfig.cgi username parameter (User Account Configuration). | ||
| CVE-2019-20072 | Med | 0.40 | 6.1 | 0.02 | Dec 30, 2019 | On Netis DL4323 devices, XSS exists via the form2Ddns.cgi hostname parameter (Dynamic DNS Configuration). | ||
| CVE-2019-20070 | Med | 0.40 | 6.1 | 0.01 | Dec 30, 2019 | On Netis DL4323 devices, XSS exists via the urlFQDN parameter to form2url.cgi (aka the Keyword field of the URL Blocking Configuration). |
- risk 0.57cvss 8.8epss 0.01
On Netis DL4323 devices, any user role can view sensitive information, such as a user password or the FTP password, via the form2saveConf.cgi page.
- risk 0.42cvss 6.5epss 0.01
On Netis DL4323 devices, CSRF exists via form2logaction.cgi to delete all logs.
- risk 0.40cvss 6.1epss 0.02
On Netis DL4323 devices, XSS exists via the form2Ddns.cgi username parameter (DynDns settings of the Dynamic DNS Configuration).
- risk 0.40cvss 6.1epss 0.02
On Netis DL4323 devices, pingrtt_v6.html has XSS (Ping6 Diagnostic).
- risk 0.40cvss 6.1epss 0.02
On Netis DL4323 devices, XSS exists via the form2userconfig.cgi username parameter (User Account Configuration).
- risk 0.40cvss 6.1epss 0.02
On Netis DL4323 devices, XSS exists via the form2Ddns.cgi hostname parameter (Dynamic DNS Configuration).
- risk 0.40cvss 6.1epss 0.01
On Netis DL4323 devices, XSS exists via the urlFQDN parameter to form2url.cgi (aka the Keyword field of the URL Blocking Configuration).