aztech records
8 published records for vendor aztech.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 2
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-287 Improper Authentication2
- CWE-255 Credentials Management Errors1
- CWE-264 Permissions, Privileges, and Access Controls1
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor1
- CWE-522 Insufficiently Protected Credentials1
- CWE-77 Improper Neutralization of Special Elements used in a Command ('Command Injection')1
The weakness classes this vendor ships most often: where to look.
CWEAll records
8 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
52Plan | CVE-2014-6436Proof of concept | Aztech ADSL DSL5018EN (1T1R), DSL705E, and DSL705EU devices improperly manage sessions, which allows remote attackers to bypass authenticatiaztech · adsl dsl5018en \(1t1r\) firmware · CWE-287 | Critical9.8 | — | 42.1% | Jan 12, 2018 |
44Plan | CVE-2014-6437Proof of concept | Aztech ADSL DSL5018EN (1T1R), DSL705E, and DSL705EU devices allow remote attackers to obtain sensitive device configuration information via aztech · adsl dsl5018en \(1t1r\) firmware · CWE-200 | Critical9.8 | — | 15.5% | Jan 12, 2018 |
41Plan | CVE-2008-6554No exploit | cgi-bin/script in Aztech ADSL2/2+ 4-port router 3.7.0 build 070426 allows remote attackers to execute arbitrary commands via shell metacharaaztech · adsl2\/2\+4-port router · CWE-78 | Critical10.0 | — | 3.7% | Mar 30, 2009 |
41Plan | CVE-2008-6588No exploit | Aztech ADSL2/2+ 4-port router has a default "isp" account with a default "isp" password, which allows remote attackers to obtain access if taztech · adsl2\/2\+4-port router · CWE-255 | Critical10.0 | — | 2.4% | Apr 3, 2009 |
39Monitor | CVE-2022-45599Proof of concept | Aztech WMB250AC Mesh Routers Firmware Version 016 2020 is vulnerable to PHP Type Juggling in file /var/www/login.php, allows attackers to gaaztech · wmb250ac firmware · CWE-522 | Critical9.8 | — | 1.0% | Feb 22, 2023 |
38Monitor | CVE-2007-4733No exploit | The Aztech DSL600EU router, when WAN access to the web interface is disabled, does not properly block inbound traffic on TCP port 80, which aztech · dsl 600eu router · CWE-264 | Critical9.3 | — | 1.8% | Sep 6, 2007 |
36Monitor | CVE-2022-45600Proof of concept | Aztech WMB250AC Mesh Routers Firmware Version 016 2020 devices improperly manage sessions, which allows remote attackers to bypass authenticaztech · wmb250ac firmware · CWE-77 | High8.8 | — | 2.3% | Feb 22, 2023 |
34Monitor | CVE-2014-6435Proof of concept | cgi-bin/AZ_Retrain.cgi in Aztech ADSL DSL5018EN (1T1R), DSL705E, and DSL705EU devices does not check for authentication, which allows remoteaztech · adsl dsl5018en \(1t1r\) firmware · CWE-287 | High7.5 | — | 12.6% | Jan 12, 2018 |
- CVE-2014-643652Plan
Aztech ADSL DSL5018EN (1T1R), DSL705E, and DSL705EU devices improperly manage sessions, which allows remote attackers to bypass authenticati
CriticalCVSS 9.8Proof of conceptEPSS 42%aztech · adsl dsl5018en \(1t1r\) firmwareJan 12, 2018
- CVE-2014-643744Plan
Aztech ADSL DSL5018EN (1T1R), DSL705E, and DSL705EU devices allow remote attackers to obtain sensitive device configuration information via
CriticalCVSS 9.8Proof of conceptEPSS 16%aztech · adsl dsl5018en \(1t1r\) firmwareJan 12, 2018
- CVE-2008-655441Plan
cgi-bin/script in Aztech ADSL2/2+ 4-port router 3.7.0 build 070426 allows remote attackers to execute arbitrary commands via shell metachara
CriticalCVSS 10.0No exploitEPSS 4%aztech · adsl2\/2\+4-port routerMar 30, 2009
- CVE-2008-658841Plan
Aztech ADSL2/2+ 4-port router has a default "isp" account with a default "isp" password, which allows remote attackers to obtain access if t
CriticalCVSS 10.0No exploitEPSS 2%aztech · adsl2\/2\+4-port routerApr 3, 2009
- CVE-2022-4559939Monitor
Aztech WMB250AC Mesh Routers Firmware Version 016 2020 is vulnerable to PHP Type Juggling in file /var/www/login.php, allows attackers to ga
CriticalCVSS 9.8Proof of conceptEPSS 1%aztech · wmb250ac firmwareFeb 22, 2023
- CVE-2007-473338Monitor
The Aztech DSL600EU router, when WAN access to the web interface is disabled, does not properly block inbound traffic on TCP port 80, which
CriticalCVSS 9.3No exploitEPSS 2%aztech · dsl 600eu routerSep 6, 2007
- CVE-2022-4560036Monitor
Aztech WMB250AC Mesh Routers Firmware Version 016 2020 devices improperly manage sessions, which allows remote attackers to bypass authentic
HighCVSS 8.8Proof of conceptEPSS 2%aztech · wmb250ac firmwareFeb 22, 2023
- CVE-2014-643534Monitor
cgi-bin/AZ_Retrain.cgi in Aztech ADSL DSL5018EN (1T1R), DSL705E, and DSL705EU devices does not check for authentication, which allows remote
HighCVSS 7.5Proof of conceptEPSS 13%aztech · adsl dsl5018en \(1t1r\) firmwareJan 12, 2018