| CVE-2015-7277 | Cri | 0.64 | 9.8 | 0.00 | | Dec 31, 2015 | The web administration interface on Amped Wireless R10000 devices with firmware 2.5.2.11 has a default password of admin for the admin account, which allows remote attackers to obtain administrative privileges by leveraging a LAN session. |
| CVE-2015-7278 | Hig | 0.57 | 8.8 | 0.00 | | Dec 31, 2015 | Cross-site request forgery (CSRF) vulnerability on Amped Wireless R10000 devices with firmware 2.5.2.11 allows remote attackers to hijack the authentication of arbitrary users. |
| CVE-2015-7279 | Med | 0.35 | 5.3 | 0.01 | | Dec 31, 2015 | Amped Wireless R10000 devices with firmware 2.5.2.11 use an improper algorithm for selecting the ID value in the header of a DNS query, which makes it easier for remote attackers to spoof responses by predicting this value. |