WAYOS
Products
9- 3 CVEs
- 1 CVE
- 1 CVE
- 1 CVE
- 1 CVE
- 1 CVE
- 1 CVE
- 1 CVE
- 0 CVEs
Recent CVEs
8| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-37794 | Cri | 0.64 | 9.8 | 0.02 | Jul 14, 2023 | WAYOS FBM-291W 19.09.11V was discovered to contain a command injection vulnerability via the component /upgrade_filter.asp. | ||
| CVE-2023-37793 | Cri | 0.64 | 9.8 | 0.01 | Jul 14, 2023 | WAYOS FBM-291W 19.09.11V was discovered to contain a buffer overflow via the component /upgrade_filter.asp. | ||
| CVE-2024-44414 | Hig | 0.57 | 8.8 | 0.01 | Oct 11, 2024 | A vulnerability was discovered in FBM_292W-21.03.10V, which has been classified as critical. This issue affects the sub_4901E0 function in the msp_info.htm file. Manipulation of the path parameter can lead to command injection. | ||
| CVE-2022-41489 | Hig | 0.53 | 8.1 | 0.00 | Oct 13, 2022 | WAYOS LQ_09 22.03.17V was discovered to contain a Cross-Site Request Forgery (CSRF) which allows attackers to send crafted requests to the server from the affected device. This vulnerability is exploitable due to a lack of authentication in the component Usb_upload.htm. | ||
| CVE-2025-11045 | Hig | 0.48 | 7.3 | 0.02 | Sep 26, 2025 | A vulnerability was identified in WAYOS LQ_04, LQ_05, LQ_06, LQ_07 and LQ_09 22.03.17. This affects an unknown function of the file /usb_paswd.asp. The manipulation of the argument Name leads to command injection. The attack can be initiated remotely. The exploit is publicly… | ||
| CVE-2024-44383 | Med | 0.44 | 6.8 | 0.01 | Sep 4, 2024 | WAYOS FBM-291W v19.09.11 is vulnerable to Command Execution via msp_info_htm. | ||
| CVE-2026-2548 | Med | 0.41 | 6.3 | 0.02 | Feb 16, 2026 | A flaw has been found in WAYOS FBM-220G 24.10.19. This affects the function sub_40F820 of the file rc. Executing a manipulation of the argument upnp_waniface/upnp_ssdp_interval/upnp_max_age can lead to command injection. The attack can be executed remotely. The vendor was… | ||
| CVE-2024-22547 | Med | 0.31 | 4.7 | 0.00 | Feb 22, 2024 | WayOS IBR-7150 <17.06.23 is vulnerable to Cross Site Scripting (XSS). |
- risk 0.64cvss 9.8epss 0.02
WAYOS FBM-291W 19.09.11V was discovered to contain a command injection vulnerability via the component /upgrade_filter.asp.
- risk 0.64cvss 9.8epss 0.01
WAYOS FBM-291W 19.09.11V was discovered to contain a buffer overflow via the component /upgrade_filter.asp.
- risk 0.57cvss 8.8epss 0.01
A vulnerability was discovered in FBM_292W-21.03.10V, which has been classified as critical. This issue affects the sub_4901E0 function in the msp_info.htm file. Manipulation of the path parameter can lead to command injection.
- risk 0.53cvss 8.1epss 0.00
WAYOS LQ_09 22.03.17V was discovered to contain a Cross-Site Request Forgery (CSRF) which allows attackers to send crafted requests to the server from the affected device. This vulnerability is exploitable due to a lack of authentication in the component Usb_upload.htm.
- risk 0.48cvss 7.3epss 0.02
A vulnerability was identified in WAYOS LQ_04, LQ_05, LQ_06, LQ_07 and LQ_09 22.03.17. This affects an unknown function of the file /usb_paswd.asp. The manipulation of the argument Name leads to command injection. The attack can be initiated remotely. The exploit is publicly…
- risk 0.44cvss 6.8epss 0.01
WAYOS FBM-291W v19.09.11 is vulnerable to Command Execution via msp_info_htm.
- risk 0.41cvss 6.3epss 0.02
A flaw has been found in WAYOS FBM-220G 24.10.19. This affects the function sub_40F820 of the file rc. Executing a manipulation of the argument upnp_waniface/upnp_ssdp_interval/upnp_max_age can lead to command injection. The attack can be executed remotely. The vendor was…
- risk 0.31cvss 4.7epss 0.00
WayOS IBR-7150 <17.06.23 is vulnerable to Cross Site Scripting (XSS).