VYPR

Home Spot Cube Firmware

by Kddi

CVEs (5)

  • CVE-2016-1137HigJan 30, 2016
    risk 0.48cvss 7.4epss 0.00

    Open redirect vulnerability on KDDI HOME SPOT CUBE devices before 2 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors.

  • CVE-2016-1140MedJan 30, 2016
    risk 0.40cvss 6.1epss 0.00

    KDDI HOME SPOT CUBE devices before 2 allow remote attackers to conduct clickjacking attacks via unspecified vectors.

  • CVE-2016-1136MedJan 30, 2016
    risk 0.35cvss 5.4epss 0.00

    Cross-site scripting (XSS) vulnerability on KDDI HOME SPOT CUBE devices before 2 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.

  • CVE-2016-1141MedJan 30, 2016
    risk 0.31cvss 4.7epss 0.01

    KDDI HOME SPOT CUBE devices before 2 allow remote authenticated users to execute arbitrary OS commands via unspecified vectors.

  • CVE-2016-1138MedJan 30, 2016
    risk 0.31cvss 4.7epss 0.00

    CRLF injection vulnerability on KDDI HOME SPOT CUBE devices before 2 allows remote attackers to inject arbitrary HTTP headers via unspecified vectors.