VYPR
Vendor

HiNet

Products
5
CVEs
11
Across products
16
Status
Private

Products

5

Recent CVEs

11
  • CVE-2019-15066CriOct 17, 2019
    risk 0.65cvss 10.0epss 0.02

    An “invalid command” handler issue was discovered in HiNet GPON firmware < I040GWR190731. It allows an attacker to execute arbitrary command through port 6998. CVSS 3.0 Base score 10.0. CVSS vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H).

  • CVE-2019-13411CriOct 17, 2019
    risk 0.65cvss 10.0epss 0.01

    An “invalid command” handler issue was discovered in HiNet GPON firmware < I040GWR190731. It allows an attacker to execute arbitrary command through port 3097. CVSS 3.0 Base score 10.0. CVSS vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H).

  • CVE-2019-15064CriOct 17, 2019
    risk 0.64cvss 9.8epss 0.01

    HiNet GPON firmware version < I040GWR190731 allows an attacker login to device without any authentication.

  • CVE-2019-15065CriOct 17, 2019
    risk 0.61cvss 9.3epss 0.01

    A service which is hosted on port 6998 in HiNet GPON firmware < I040GWR190731 allows an attacker to execute a specific command to read arbitrary files. CVSS 3.0 Base score 9.3. CVSS vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L).

  • CVE-2019-13412CriOct 17, 2019
    risk 0.61cvss 9.3epss 0.01

    A service which is hosted on port 3097 in HiNet GPON firmware < I040GWR190731 allows an attacker to execute a specific command to read arbitrary files. CVSS 3.0 Base score 9.3. CVSS vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L).

  • CVE-2022-35222MedAug 2, 2022
    risk 0.44cvss 6.8epss 0.00

    HiCOS Citizen verification component has a stack-based buffer overflow vulnerability due to insufficient parameter length validation. An unauthenticated physical attacker can exploit this vulnerability to execute arbitrary code, manipulate system command or disrupt service.

  • CVE-2022-32962MedJul 20, 2022
    risk 0.44cvss 6.8epss 0.00

    HiCOS’ client-side citizen certificate component has a double free vulnerability. An unauthenticated physical attacker can exploit this vulnerability to corrupt memory and execute arbitrary code, manipulate system data or terminate service.

  • CVE-2022-32961MedJul 20, 2022
    risk 0.44cvss 6.8epss 0.00

    HICOS’ client-side citizen digital certificate component has a stack-based buffer overflow vulnerability when reading IC card due to insufficient parameter length validation for token information. An unauthenticated physical attacker can exploit this vulnerability to execute…

  • CVE-2022-32960MedJul 20, 2022
    risk 0.44cvss 6.8epss 0.00

    HiCOS’ client-side citizen digital certificate component has a stack-based buffer overflow vulnerability when reading IC card due to insufficient parameter length validation for card number. An unauthenticated physical attacker can exploit this vulnerability to execute…

  • CVE-2022-32959MedJul 20, 2022
    risk 0.44cvss 6.8epss 0.00

    HiCOS’ client-side citizen digital certificate component has a stack-based buffer overflow vulnerability when reading IC card due to insufficient parameter length validation for OS information. An unauthenticated physical attacker can exploit this vulnerability to execute…

  • CVE-2000-0964Dec 19, 2000
    risk 0.00cvss epss 0.04

    Buffer overflow in the web administration service for the HiNet LP5100 IP-phone allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a long GET request.