VYPR
Vendor

WAYOS

Products
9
CVEs
8
Across products
10
Status
Private

Products

9

Recent CVEs

8
  • CVE-2023-37794CriJul 14, 2023
    risk 0.64cvss 9.8epss 0.02

    WAYOS FBM-291W 19.09.11V was discovered to contain a command injection vulnerability via the component /upgrade_filter.asp.

  • CVE-2023-37793CriJul 14, 2023
    risk 0.64cvss 9.8epss 0.01

    WAYOS FBM-291W 19.09.11V was discovered to contain a buffer overflow via the component /upgrade_filter.asp.

  • CVE-2024-44414HigOct 11, 2024
    risk 0.57cvss 8.8epss 0.01

    A vulnerability was discovered in FBM_292W-21.03.10V, which has been classified as critical. This issue affects the sub_4901E0 function in the msp_info.htm file. Manipulation of the path parameter can lead to command injection.

  • CVE-2022-41489HigOct 13, 2022
    risk 0.53cvss 8.1epss 0.00

    WAYOS LQ_09 22.03.17V was discovered to contain a Cross-Site Request Forgery (CSRF) which allows attackers to send crafted requests to the server from the affected device. This vulnerability is exploitable due to a lack of authentication in the component Usb_upload.htm.

  • CVE-2025-11045HigSep 26, 2025
    risk 0.48cvss 7.3epss 0.02

    A vulnerability was identified in WAYOS LQ_04, LQ_05, LQ_06, LQ_07 and LQ_09 22.03.17. This affects an unknown function of the file /usb_paswd.asp. The manipulation of the argument Name leads to command injection. The attack can be initiated remotely. The exploit is publicly…

  • CVE-2024-44383MedSep 4, 2024
    risk 0.44cvss 6.8epss 0.01

    WAYOS FBM-291W v19.09.11 is vulnerable to Command Execution via msp_info_htm.

  • CVE-2026-2548MedFeb 16, 2026
    risk 0.41cvss 6.3epss 0.02

    A flaw has been found in WAYOS FBM-220G 24.10.19. This affects the function sub_40F820 of the file rc. Executing a manipulation of the argument upnp_waniface/upnp_ssdp_interval/upnp_max_age can lead to command injection. The attack can be executed remotely. The vendor was…

  • CVE-2024-22547MedFeb 22, 2024
    risk 0.31cvss 4.7epss 0.00

    WayOS IBR-7150 <17.06.23 is vulnerable to Cross Site Scripting (XSS).