VYPR
Vendor

Corega

Products
10
CVEs
12
Across products
15
Status
Private

Products

10

Recent CVEs

12
  • CVE-2015-7792CriDec 30, 2015
    risk 0.64cvss 9.8epss 0.03

    Corega CG-WLBARGS devices allow remote attackers to perform administrative operations via unspecified vectors.

  • CVE-2016-7811HigJun 9, 2017
    risk 0.57cvss 8.8epss 0.00

    Corega CG-WLR300NX firmware Ver. 1.20 and earlier allows an attacker on the same network segment to bypass access restriction to perform arbitrary operations via unspecified vectors.

  • CVE-2016-7809HigJun 9, 2017
    risk 0.57cvss 8.8epss 0.00

    Cross-site request forgery (CSRF) vulnerability in Corega CG-WLR300NX firmware Ver. 1.20 and earlier allows remote attackers to hijack the authentication of logged in user to conduct unintended operations via unspecified vectors.

  • CVE-2016-1158HigMar 3, 2016
    risk 0.57cvss 8.8epss 0.00

    Cross-site request forgery (CSRF) vulnerability on Corega CG-WLBARGMH and CG-WLBARGNL devices allows remote attackers to hijack the authentication of administrators for requests that perform administrative functions.

  • CVE-2016-4822HigJun 25, 2016
    risk 0.52cvss 8.0epss 0.01

    Corega CG-WLBARGL devices allow remote authenticated users to execute arbitrary commands via unspecified vectors.

  • CVE-2016-4823HigJun 25, 2016
    risk 0.49cvss 7.5epss 0.01

    Corega CG-WLBARAGM devices allow remote attackers to cause a denial of service (reboot) via unspecified vectors.

  • CVE-2017-10813MedSep 15, 2017
    risk 0.44cvss 6.8epss 0.00

    CG-WLR300NM Firmware version 1.90 and earlier allows an attacker to execute arbitrary OS commands via unspecified vectors.

  • CVE-2016-7808MedJun 9, 2017
    risk 0.40cvss 6.1epss 0.00

    Cross-site scripting vulnerability in Corega CG-WLBARGMH and CG-WLBARGNL allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

  • CVE-2015-7794MedDec 30, 2015
    risk 0.38cvss 5.8epss 0.01

    Corega CG-WLNCM4G devices provide an open DNS resolver, which allows remote attackers to cause a denial of service (traffic amplification) via crafted queries.

  • CVE-2015-7793MedDec 30, 2015
    risk 0.38cvss 5.8epss 0.01

    Corega CG-WLBARAGM devices provide an open proxy service, which allows remote attackers to trigger outbound network traffic via unspecified vectors.

  • CVE-2016-4824MedJun 25, 2016
    risk 0.34cvss 5.3epss 0.00

    The Wi-Fi Protected Setup (WPS) implementation on Corega CG-WLR300GNV and CG-WLR300GNV-W devices does not restrict the number of PIN authentication attempts, which makes it easier for remote attackers to obtain network access via a brute-force attack.

  • CVE-2016-7810MedJun 9, 2017
    risk 0.31cvss 4.8epss 0.00

    Cross-site scripting vulnerability in Corega CG-WLR300NX firmware Ver. 1.20 and earlier allows attacker with administrator rights to inject arbitrary web script or HTML via unspecified vectors.