compal records
4 published records for vendor compal.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 1 · 25%
- Pre-auth RCE
- 2
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')2
- CWE-120 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')1
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')1
The weakness classes this vendor ships most often: where to look.
CWEAll records
4 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
42Plan | CVE-2019-19494Weaponized | Broadcom based cable modems across multiple vendors are vulnerable to a buffer overflow, which allows a remote attacker to execute arbitrarysagemcom · f\@st 3890 firmware · CWE-120 | High8.8 | — | 23.1% | Jan 9, 2020 |
40Plan | CVE-2019-13025Proof of concept | Compal CH7465LG CH7465LG-NCIP-6.12.18.24-5p8-NOSH devices have Incorrect Access Control because of Improper Input Validation.compal · ch7465lg firmware · CWE-78 | Critical9.8 | — | 3.3% | Oct 2, 2019 |
36Monitor | CVE-2019-17499No exploit | The setter.xml component of the Common Gateway Interface on Compal CH7465LG 6.12.18.25-2p4 devices does not properly validate ping command acompal · ch7465lg firmware · CWE-78 | High8.8 | — | 3.2% | Oct 11, 2019 |
21Monitor | CVE-2019-17224No exploit | The web interface of the Compal Broadband CH7465LG modem (version CH7465LG-NCIP-6.12.18.25-2p6-NOSH) is vulnerable to a /%2f/ path traversalcompal · ch7465lg firmware · CWE-22 | Medium5.3 | — | 1.2% | Oct 28, 2019 |
- CVE-2019-1949442Plan
Broadcom based cable modems across multiple vendors are vulnerable to a buffer overflow, which allows a remote attacker to execute arbitrary
HighCVSS 8.8WeaponizedEPSS 23%sagemcom · f\@st 3890 firmwareJan 9, 2020
- CVE-2019-1302540Plan
Compal CH7465LG CH7465LG-NCIP-6.12.18.24-5p8-NOSH devices have Incorrect Access Control because of Improper Input Validation.
CriticalCVSS 9.8Proof of conceptEPSS 3%compal · ch7465lg firmwareOct 2, 2019
- CVE-2019-1749936Monitor
The setter.xml component of the Common Gateway Interface on Compal CH7465LG 6.12.18.25-2p4 devices does not properly validate ping command a
HighCVSS 8.8No exploitEPSS 3%compal · ch7465lg firmwareOct 11, 2019
- CVE-2019-1722421Monitor
The web interface of the Compal Broadband CH7465LG modem (version CH7465LG-NCIP-6.12.18.25-2p6-NOSH) is vulnerable to a /%2f/ path traversal
MediumCVSS 5.3No exploitEPSS 1%compal · ch7465lg firmwareOct 28, 2019