VYPR

VDSL2 Modem HG 150-UB

by Fiberhome

CVEs (3)

  • CVE-2018-9248CriApr 4, 2018
    risk 0.68cvss 9.8epss 0.14

    FiberHome VDSL2 Modem HG 150-UB devices allow authentication bypass via a "Cookie: Name=0admin" header.

  • CVE-2022-36200HigAug 29, 2022
    risk 0.49cvss 7.5epss 0.02

    In FiberHome VDSL2 Modem HG150-Ub_V3.0, Credentials of Admin are submitted in URL, which can be logged/sniffed.

  • CVE-2021-41946MedMay 18, 2022
    risk 0.35cvss 5.4epss 0.02

    In FiberHome VDSL2 Modem HG150-Ub_V3.0, a stored cross-site scripting (XSS) vulnerability in Parental Control --> Access Time Restriction --> Username field, a user cannot delete the rule due to the XSS.