NetModule kayıtları
netmodule üreticisine ait 6 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 0
- Düzeltme kaydı olan
- %50
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')1
- CWE-384 Session Fixation1
- CWE-522 Insufficiently Protected Credentials1
- CWE-532 Insertion of Sensitive Information into Log File1
- CWE-77 Improper Neutralization of Special Elements used in a Command ('Command Injection')1
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
6 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
44Planlayın | CVE-2023-0861Kavram kanıtı | Authenticated Command Injection in NetModule NSRWnetmodule · netmodule router software · CWE-77 | Yüksek8,8 | — | %28,7 | 16 Şub 2023 |
39İzleyin | CVE-2021-39290İstismar yok | Certain NetModule devices allow Limited Session Fixation via PHPSESSID.netmodule · netmodule router software · CWE-384 | Kritik9,8 | — | %1,5 | 23 Ağu 2021 |
36İzleyin | CVE-2023-0862İstismar yok | Path Traversal in NetModule NSRWnetmodule · netmodule router software · CWE-22 | Yüksek8,8 | — | %2,4 | 16 Şub 2023 |
35İzleyin | CVE-2021-39291İstismar yok | Certain NetModule devices allow credentials via GET parameters to CLI-PHP.netmodule · netmodule router software · CWE-532 | Yüksek8,8 | — | %1,5 | 23 Ağu 2021 |
30İzleyin | CVE-2021-39289İstismar yok | Certain NetModule devices have Insecure Password Handling (cleartext or reversible encryption), These models with firmware before 4.3.0.113,netmodule · netmodule router software · CWE-522 | Yüksek7,5 | — | %1,1 | 23 Ağu 2021 |
26İzleyin | CVE-2023-46306İstismar yok | The web administration interface in NetModule Router Software (NRSW) 4.6 before 4.6.0.106 and 4.8 before 4.8.0.101 executes an OS command conetmodule · netmodule router software · CWE-78 | Orta6,6 | — | %1,0 | 22 Eki 2023 |
- CVE-2023-086144Planlayın
Authenticated Command Injection in NetModule NSRW
YüksekCVSS 8,8Kavram kanıtıEPSS %29netmodule · netmodule router software16 Şub 2023
- CVE-2021-3929039İzleyin
Certain NetModule devices allow Limited Session Fixation via PHPSESSID.
KritikCVSS 9,8İstismar yokEPSS %2netmodule · netmodule router software23 Ağu 2021
- CVE-2023-086236İzleyin
Path Traversal in NetModule NSRW
YüksekCVSS 8,8İstismar yokEPSS %2netmodule · netmodule router software16 Şub 2023
- CVE-2021-3929135İzleyin
Certain NetModule devices allow credentials via GET parameters to CLI-PHP.
YüksekCVSS 8,8İstismar yokEPSS %2netmodule · netmodule router software23 Ağu 2021
- CVE-2021-3928930İzleyin
Certain NetModule devices have Insecure Password Handling (cleartext or reversible encryption), These models with firmware before 4.3.0.113,
YüksekCVSS 7,5İstismar yokEPSS %1netmodule · netmodule router software23 Ağu 2021
- CVE-2023-4630626İzleyin
The web administration interface in NetModule Router Software (NRSW) 4.6 before 4.6.0.106 and 4.8 before 4.8.0.101 executes an OS command co
OrtaCVSS 6,6İstismar yokEPSS %1netmodule · netmodule router software22 Eki 2023