VYPR
Vendor

Kddi

Products
4
CVEs
11
Across products
11
Status
Private

Products

4

Recent CVEs

11
  • CVE-2017-2186HigJul 7, 2017
    risk 0.57cvss 8.8epss 0.01

    HOME SPOT CUBE2 firmware V101 and earlier allows an attacker to bypass authentication to load malicious firmware via WebUI.

  • CVE-2017-2185HigJul 7, 2017
    risk 0.57cvss 8.8epss 0.01

    HOME SPOT CUBE2 firmware V101 and earlier allows authenticated attackers to execute arbitrary OS commands via WebUI.

  • CVE-2017-2184HigJul 7, 2017
    risk 0.57cvss 8.8epss 0.01

    Buffer overflow in HOME SPOT CUBE2 firmware V101 and earlier allows an attacker to execute arbitrary code via WebUI.

  • CVE-2017-2183HigJul 7, 2017
    risk 0.52cvss 8.0epss 0.01

    HOME SPOT CUBE2 firmware V101 and earlier allows authenticated attackers to execute arbitrary OS commands via Clock Settings.

  • CVE-2017-2289HigAug 18, 2017
    risk 0.51cvss 7.8epss 0.00

    Untrusted search path vulnerability in Installer of Qua station connection tool for Windows version 1.00.03 allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.

  • CVE-2016-1137HigJan 30, 2016
    risk 0.48cvss 7.4epss 0.00

    Open redirect vulnerability on KDDI HOME SPOT CUBE devices before 2 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors.

  • CVE-2016-1140MedJan 30, 2016
    risk 0.40cvss 6.1epss 0.00

    KDDI HOME SPOT CUBE devices before 2 allow remote attackers to conduct clickjacking attacks via unspecified vectors.

  • CVE-2016-1136MedJan 30, 2016
    risk 0.35cvss 5.4epss 0.00

    Cross-site scripting (XSS) vulnerability on KDDI HOME SPOT CUBE devices before 2 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.

  • CVE-2016-1141MedJan 30, 2016
    risk 0.31cvss 4.7epss 0.01

    KDDI HOME SPOT CUBE devices before 2 allow remote authenticated users to execute arbitrary OS commands via unspecified vectors.

  • CVE-2016-1138MedJan 30, 2016
    risk 0.31cvss 4.7epss 0.00

    CRLF injection vulnerability on KDDI HOME SPOT CUBE devices before 2 allows remote attackers to inject arbitrary HTTP headers via unspecified vectors.

  • CVE-2007-3692Jul 11, 2007
    risk 0.00cvss epss 0.01

    Directory traversal vulnerability in download.cgi in EZFactory KDDI Download CGI 1.x allows remote attackers to read and download arbitrary files via a .. (dot dot) in the name parameter.