Записи iball
9 опубликованных записей вендора iball.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 0
- С записью об исправлении
- 0 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-352 Cross-Site Request Forgery (CSRF)2
- CWE-798 Use of Hard-coded Credentials2
- CWE-312 Cleartext Storage of Sensitive Information1
- CWE-425 Direct Request ('Forced Browsing')1
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')1
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
9 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
44В плане | CVE-2017-14244Proof of concept | An authentication bypass vulnerability on iBall Baton ADSL2+ Home Router FW_iB-LR7011A_1.0.2 devices potentially allows attackers to directliball · ib-wra150n firmware · CWE-425 | Критическая9,8 | — | 17,1 % | 17 сент. 2017 г. |
44В плане | CVE-2017-6558Proof of concept | iball Baton 150M iB-WRA150N v1 00000001 1.2.6 build 110401 Rel.47776n devices are prone to an authentication bypass vulnerability that allowiball · ib-wra150n firmware · CWE-798 | Критическая9,8 | — | 15,3 % | 9 мар. 2017 г. |
40В плане | CVE-2018-6387Эксплойта нет | iBall iB-WRA150N 1.2.6 build 110401 Rel.47776n devices have a hardcoded password of admin for the admin account, a hardcoded password of supiball · ib-wra150n firmware · CWE-798 | Критическая9,8 | — | 1,8 % | 29 янв. 2018 г. |
37Наблюдать | CVE-2018-6388Proof of concept | iBall iB-WRA150N 1.2.6 build 110401 Rel.47776n devices allow remote authenticated users to execute arbitrary OS commands via shell metacharaiball · ib-wra150n firmware · CWE-78 | Высокая8,8 | — | 5,9 % | 29 янв. 2018 г. |
36Наблюдать | CVE-2017-11169Эксплойта нет | Privilege Escalation on iBall iB-WRA300N3GT iB-WRA300N3GT_1.1.1 devices allows remote authenticated users to obtain root privileges by leveriball · ib-wra300n3gt firmware | Высокая8,8 | — | 2,2 % | 13 нояб. 2017 г. |
27Наблюдать | CVE-2018-20008Эксплойта нет | iBall Baton iB-WRB302N20122017 devices have improper access control over the UART interface, allowing physical attackers to discover Wi-Fi ciball · ib-wrb302n firmware · CWE-312 | Средняя6,8 | — | 0,3 % | 28 мая 2019 г. |
26Наблюдать | CVE-2020-15043Эксплойта нет | iBall WRB303N devices allow CSRF attacks, as demonstrated by enabling remote management, enabling DHCP, or modifying the subnet range for IPiball · wrb303n firmware · CWE-352 | Средняя6,5 | — | 0,4 % | 29 июн. 2020 г. |
26Наблюдать | CVE-2020-29292Эксплойта нет | iBall WRD12EN 1.0.0 devices allow cross-site request forgery (CSRF) attacks as demonstrated by enabling DNS settings or modifying the range iball · wrd12en firmware · CWE-352 | Средняя6,5 | — | 0,4 % | 30 дек. 2021 г. |
24Наблюдать | CVE-2018-6355Эксплойта нет | /goform/setLang on iBall 300M devices with "iB-WRB302N_1.0.1-Sep 8 2017" firmware has Unauthenticated Stored Cross Site Scripting via the laiball · ib-wrb302n firmware · CWE-79 | Средняя6,1 | — | 0,6 % | 30 янв. 2018 г. |
- CVE-2017-1424444В плане
An authentication bypass vulnerability on iBall Baton ADSL2+ Home Router FW_iB-LR7011A_1.0.2 devices potentially allows attackers to directl
КритическаяCVSS 9,8Proof of conceptEPSS 17 %iball · ib-wra150n firmware17 сент. 2017 г.
- CVE-2017-655844В плане
iball Baton 150M iB-WRA150N v1 00000001 1.2.6 build 110401 Rel.47776n devices are prone to an authentication bypass vulnerability that allow
КритическаяCVSS 9,8Proof of conceptEPSS 15 %iball · ib-wra150n firmware9 мар. 2017 г.
- CVE-2018-638740В плане
iBall iB-WRA150N 1.2.6 build 110401 Rel.47776n devices have a hardcoded password of admin for the admin account, a hardcoded password of sup
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %iball · ib-wra150n firmware29 янв. 2018 г.
- CVE-2018-638837Наблюдать
iBall iB-WRA150N 1.2.6 build 110401 Rel.47776n devices allow remote authenticated users to execute arbitrary OS commands via shell metachara
ВысокаяCVSS 8,8Proof of conceptEPSS 6 %iball · ib-wra150n firmware29 янв. 2018 г.
- CVE-2017-1116936Наблюдать
Privilege Escalation on iBall iB-WRA300N3GT iB-WRA300N3GT_1.1.1 devices allows remote authenticated users to obtain root privileges by lever
ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %iball · ib-wra300n3gt firmware13 нояб. 2017 г.
- CVE-2018-2000827Наблюдать
iBall Baton iB-WRB302N20122017 devices have improper access control over the UART interface, allowing physical attackers to discover Wi-Fi c
СредняяCVSS 6,8Эксплойта нетEPSS 0 %iball · ib-wrb302n firmware28 мая 2019 г.
- CVE-2020-1504326Наблюдать
iBall WRB303N devices allow CSRF attacks, as demonstrated by enabling remote management, enabling DHCP, or modifying the subnet range for IP
СредняяCVSS 6,5Эксплойта нетEPSS 0 %iball · wrb303n firmware29 июн. 2020 г.
- CVE-2020-2929226Наблюдать
iBall WRD12EN 1.0.0 devices allow cross-site request forgery (CSRF) attacks as demonstrated by enabling DNS settings or modifying the range
СредняяCVSS 6,5Эксплойта нетEPSS 0 %iball · wrd12en firmware30 дек. 2021 г.
- CVE-2018-635524Наблюдать
/goform/setLang on iBall 300M devices with "iB-WRB302N_1.0.1-Sep 8 2017" firmware has Unauthenticated Stored Cross Site Scripting via the la
СредняяCVSS 6,1Эксплойта нетEPSS 1 %iball · ib-wrb302n firmware30 янв. 2018 г.