VYPR

RX1800 WiFi 6 Router

by Victure

CVEs (5)

  • CVE-2024-53937HigDec 2, 2024
    risk 0.57cvss 8.8epss 0.00

    An issue was discovered on Victure RX1800 WiFi 6 Router (software EN_V1.0.0_r12_110933, hardware 1.0) devices. The TELNET service is enabled by default with admin/admin as default credentials and is exposed over the LAN. The allows attackers to execute arbitrary commands with…

  • CVE-2024-53941HigDec 2, 2024
    risk 0.57cvss 8.8epss 0.01

    An issue was discovered in Victure RX1800 WiFi 6 Router (software EN_V1.0.0_r12_110933, hardware 1.0) devices. A remote attacker (in proximity to a Wi-Fi network) can derive the default Wi-Fi PSK value via the last 4 octets of the BSSID.

  • CVE-2024-53940HigDec 2, 2024
    risk 0.57cvss 8.8epss 0.02

    An issue was discovered in Victure RX1800 WiFi 6 Router (software EN_V1.0.0_r12_110933, hardware 1.0) devices. Certain /cgi-bin/luci/admin endpoints are vulnerable to command injection. Attackers can exploit this by sending crafted payloads through parameters intended for the…

  • CVE-2024-53939HigDec 2, 2024
    risk 0.57cvss 8.8epss 0.03

    An issue was discovered in Victure RX1800 WiFi 6 Router (software EN_V1.0.0_r12_110933, hardware 1.0) devices. The /cgi-bin/luci/admin/opsw/Dual_freq_un_apple endpoint is vulnerable to command injection through the 2.4 GHz and 5 GHz name parameters, allowing an attacker to…

  • CVE-2024-53938HigDec 2, 2024
    risk 0.57cvss 8.8epss 0.00

    An issue was discovered in Victure RX1800 WiFi 6 Router (software EN_V1.0.0_r12_110933, hardware 1.0) devices. The TELNET service is enabled by default and exposed over the LAN. The root account is accessible without a password, allowing attackers to achieve full control over…