evenroute kayıtları
evenroute üreticisine ait 6 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 1
- Düzeltme kaydı olan
- %0
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-287 Improper Authentication2
- CWE-521 Weak Password Requirements1
- CWE-532 Insertion of Sensitive Information into Log File1
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')1
- CWE-862 Missing Authorization1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
6 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
40Planlayın | CVE-2020-11967İstismar yok | In IQrouter through 3.3.1, remote attackers can control the device (restart network, reboot, upgrade, reset) because of Incorrect Access Conevenroute · iqrouter firmware · CWE-862 | Kritik9,8 | — | %3,3 | 21 Nis 2020 |
40Planlayın | CVE-2020-11963İstismar yok | IQrouter through 3.3.1, when unconfigured, has multiple remote code execution vulnerabilities in the web-panel because of Bash Shell Metachaevenroute · iqrouter firmware · CWE-78 | Kritik9,8 | — | %3,2 | 21 Nis 2020 |
40Planlayın | CVE-2020-11966İstismar yok | In IQrouter through 3.3.1, the Lua function reset_password in the web-panel allows remote attackers to change the root password arbitrarily.evenroute · iqrouter firmware · CWE-521 | Kritik9,8 | — | %3,1 | 21 Nis 2020 |
40Planlayın | CVE-2020-11965İstismar yok | In IQrouter through 3.3.1, there is a root user without a password, which allows attackers to gain full remote access via SSH.evenroute · iqrouter firmware · CWE-287 | Kritik9,8 | — | %2,1 | 21 Nis 2020 |
31İzleyin | CVE-2020-11968İstismar yok | In the web-panel in IQrouter through 3.3.1, remote attackers can read system logs because of Incorrect Access Control.evenroute · iqrouter firmware · CWE-532 | Yüksek7,5 | — | %2,7 | 21 Nis 2020 |
31İzleyin | CVE-2020-11964İstismar yok | In IQrouter through 3.3.1, the Lua function diag_set_password in the web-panel allows remote attackers to change the root password arbitrarievenroute · iqrouter firmware · CWE-287 | Yüksek7,5 | — | %2,3 | 21 Nis 2020 |
- CVE-2020-1196740Planlayın
In IQrouter through 3.3.1, remote attackers can control the device (restart network, reboot, upgrade, reset) because of Incorrect Access Con
KritikCVSS 9,8İstismar yokEPSS %3evenroute · iqrouter firmware21 Nis 2020
- CVE-2020-1196340Planlayın
IQrouter through 3.3.1, when unconfigured, has multiple remote code execution vulnerabilities in the web-panel because of Bash Shell Metacha
KritikCVSS 9,8İstismar yokEPSS %3evenroute · iqrouter firmware21 Nis 2020
- CVE-2020-1196640Planlayın
In IQrouter through 3.3.1, the Lua function reset_password in the web-panel allows remote attackers to change the root password arbitrarily.
KritikCVSS 9,8İstismar yokEPSS %3evenroute · iqrouter firmware21 Nis 2020
- CVE-2020-1196540Planlayın
In IQrouter through 3.3.1, there is a root user without a password, which allows attackers to gain full remote access via SSH.
KritikCVSS 9,8İstismar yokEPSS %2evenroute · iqrouter firmware21 Nis 2020
- CVE-2020-1196831İzleyin
In the web-panel in IQrouter through 3.3.1, remote attackers can read system logs because of Incorrect Access Control.
YüksekCVSS 7,5İstismar yokEPSS %3evenroute · iqrouter firmware21 Nis 2020
- CVE-2020-1196431İzleyin
In IQrouter through 3.3.1, the Lua function diag_set_password in the web-panel allows remote attackers to change the root password arbitrari
YüksekCVSS 7,5İstismar yokEPSS %2evenroute · iqrouter firmware21 Nis 2020