VYPR

Vendor CVEs

Hathway

All CVEs

27 total · sorted by risk
  • CVE-2023-51741HigJan 17, 2024
    risk 0.49cvss 7.5epss 0.00

    This vulnerability exist in Skyworth Router CM5100, version 4.1.1.24, due to transmission of authentication credentials in plaintext over the network. A remote attacker could exploit this vulnerability by eavesdropping on the victim’s network traffic to extract username and…

  • CVE-2023-51740HigJan 17, 2024
    risk 0.49cvss 7.5epss 0.00

    This vulnerability exist in Skyworth Router CM5100, version 4.1.1.24, due to transmission of authentication credentials in plaintext over the network. A remote attacker could exploit this vulnerability by eavesdropping on the victim’s network traffic to extract username and…

  • CVE-2023-51739MedJan 17, 2024
    risk 0.45cvss 6.9epss 0.00

    This vulnerability exist in Skyworth Router CM5100, version 4.1.1.24, due to insufficient validation of user supplied input for the Device Name parameter at its web interface. A remote attacker could exploit this vulnerability by supplying specially crafted input to the…

  • CVE-2023-51738MedJan 17, 2024
    risk 0.45cvss 6.9epss 0.00

    This vulnerability exist in Skyworth Router CM5100, version 4.1.1.24, due to insufficient validation of user supplied input for the Network Name (SSID) parameter at its web interface. A remote attacker could exploit this vulnerability by supplying specially crafted input to the…

  • CVE-2023-51737MedJan 17, 2024
    risk 0.45cvss 6.9epss 0.00

    This vulnerability exist in Skyworth Router CM5100, version 4.1.1.24, due to insufficient validation of user supplied input for the Preshared Phrase parameter at its web interface. A remote attacker could exploit this vulnerability by supplying specially crafted input to the…

  • CVE-2023-51736MedJan 17, 2024
    risk 0.45cvss 6.9epss 0.00

    This vulnerability exist in Skyworth Router CM5100, version 4.1.1.24, due to insufficient validation of user supplied input for the L2TP/PPTP Username parameter at its web interface. A remote attacker could exploit this vulnerability by supplying specially crafted input to the…

  • CVE-2023-51735MedJan 17, 2024
    risk 0.45cvss 6.9epss 0.00

    This vulnerability exist in Skyworth Router CM5100, version 4.1.1.24, due to insufficient validation of user supplied input for the Pre-shared key parameter at its web interface. A remote attacker could exploit this vulnerability by supplying specially crafted input to the…

  • CVE-2023-51734MedJan 17, 2024
    risk 0.45cvss 6.9epss 0.00

    This vulnerability exist in Skyworth Router CM5100, version 4.1.1.24, due to insufficient validation of user supplied input for the Identity parameter under Remote endpoint settings at its web interface. A remote attacker could exploit this vulnerability by supplying specially…

  • CVE-2023-51733MedJan 17, 2024
    risk 0.45cvss 6.9epss 0.00

    This vulnerability exist in Skyworth Router CM5100, version 4.1.1.24, due to insufficient validation of user supplied input for the Identity parameter under Local endpoint settings at its web interface. A remote attacker could exploit this vulnerability by supplying specially…

  • CVE-2023-51732MedJan 17, 2024
    risk 0.45cvss 6.9epss 0.00

    This vulnerability exist in Skyworth Router CM5100, version 4.1.1.24, due to insufficient validation of user supplied input for the IPsec Tunnel Name parameter at its web interface. A remote attacker could exploit this vulnerability by supplying specially crafted input to the…

  • CVE-2023-51731MedJan 17, 2024
    risk 0.45cvss 6.9epss 0.00

    This vulnerability exist in Skyworth Router CM5100, version 4.1.1.24, due to insufficient validation of user supplied input for the Hostname parameter at its web interface. A remote attacker could exploit this vulnerability by supplying specially crafted input to the parameter…

  • CVE-2023-51730MedJan 17, 2024
    risk 0.45cvss 6.9epss 0.00

    This vulnerability exist in Skyworth Router CM5100, version 4.1.1.24, due to insufficient validation of user supplied input for the DDNS Password parameter at its web interface. A remote attacker could exploit this vulnerability by supplying specially crafted input to the…

  • CVE-2023-51729MedJan 17, 2024
    risk 0.45cvss 6.9epss 0.00

    This vulnerability exist in Skyworth Router CM5100, version 4.1.1.24, due to insufficient validation of user supplied input for the DDNS Username parameter at its web interface. A remote attacker could exploit this vulnerability by supplying specially crafted input to the…

  • CVE-2023-51728MedJan 17, 2024
    risk 0.45cvss 6.9epss 0.00

    This vulnerability exist in Skyworth Router CM5100, version 4.1.1.24, due to insufficient validation of user supplied input for the SMTP Password parameter at its web interface. A remote attacker could exploit this vulnerability by supplying specially crafted input to the…

  • CVE-2023-51727MedJan 17, 2024
    risk 0.45cvss 6.9epss 0.00

    This vulnerability exist in Skyworth Router CM5100, version 4.1.1.24, due to insufficient validation of user supplied input for the SMTP Username parameter at its web interface. A remote attacker could exploit this vulnerability by supplying specially crafted input to the…

  • CVE-2023-51726MedJan 17, 2024
    risk 0.45cvss 6.9epss 0.00

    This vulnerability exist in Skyworth Router CM5100, version 4.1.1.24, due to insufficient validation of user supplied input for the SMTP Server Name parameter at its web interface. A remote attacker could exploit this vulnerability by supplying specially crafted input to the…

  • CVE-2023-51725MedJan 17, 2024
    risk 0.45cvss 6.9epss 0.00

    This vulnerability exist in Skyworth Router CM5100, version 4.1.1.24, due to insufficient validation of user supplied input for the Contact Email Address parameter at its web interface. A remote attacker could exploit this vulnerability by supplying specially crafted input to…

  • CVE-2023-51724MedJan 17, 2024
    risk 0.45cvss 6.9epss 0.00

    This vulnerability exist in Skyworth Router CM5100, version 4.1.1.24, due to insufficient validation of user supplied input for the URL parameter at its web interface. A remote attacker could exploit this vulnerability by supplying specially crafted input to the parameter at…

  • CVE-2023-51723MedJan 17, 2024
    risk 0.45cvss 6.9epss 0.00

    This vulnerability exist in Skyworth Router CM5100, version 4.1.1.24, due to insufficient validation of user supplied input for the Description parameter at its web interface. A remote attacker could exploit this vulnerability by supplying specially crafted input to the…

  • CVE-2023-51722MedJan 17, 2024
    risk 0.45cvss 6.9epss 0.00

    This vulnerability exist in Skyworth Router CM5100, version 4.1.1.24, due to insufficient validation of user supplied input for the Time Server 3 parameter at its web interface. A remote attacker could exploit this vulnerability by supplying specially crafted input to the…

  • CVE-2023-51721MedJan 17, 2024
    risk 0.45cvss 6.9epss 0.00

    This vulnerability exist in Skyworth Router CM5100, version 4.1.1.24, due to insufficient validation of user supplied input for the Time Server 2 parameter at its web interface. A remote attacker could exploit this vulnerability by supplying specially crafted input to the…

  • CVE-2023-51720MedJan 17, 2024
    risk 0.45cvss 6.9epss 0.00

    This vulnerability exist in Skyworth Router CM5100, version 4.1.1.24, due to insufficient validation of user supplied input for the Time Server 1 parameter at its web interface. A remote attacker could exploit this vulnerability by supplying specially crafted input to the…

  • CVE-2023-51719MedJan 17, 2024
    risk 0.45cvss 6.9epss 0.00

    This vulnerability exist in Skyworth Router CM5100, version 4.1.1.24, due to insufficient validation of user supplied input for the Traceroute parameter at its web interface. A remote attacker could exploit this vulnerability by supplying specially crafted input to the…

  • CVE-2023-51743MedJan 17, 2024
    risk 0.42cvss 6.5epss 0.01

    This vulnerability exist in Skyworth Router CM5100, version 4.1.1.24, due to insufficient validation of user supplied input for the Set Upstream Channel ID (UCID) parameter at its web interface. A remote attacker could exploit this vulnerability by supplying specially crafted…

  • CVE-2023-51742MedJan 17, 2024
    risk 0.42cvss 6.5epss 0.01

    This vulnerability exist in Skyworth Router CM5100, version 4.1.1.24, due to insufficient validation of user supplied input for the Add Downstream Frequency parameter at its web interface. A remote attacker could exploit this vulnerability by supplying specially crafted input to…

  • CVE-2024-44815MedSep 10, 2024
    risk 0.30cvss 4.6epss 0.01

    Vulnerability in Hathway Skyworth Router CM5100 v.4.1.1.24 allows a physically proximate attacker to obtain user credentials via SPI flash Firmware W25Q64JV.

  • CVE-2024-46383LowNov 15, 2024
    risk 0.16cvss 2.4epss 0.00

    Hathway Skyworth Router CM5100-511 v4.1.1.24 was discovered to store sensitive information about USB and Wifi connected devices in plaintext.