corega records
16 published records for vendor corega.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 2
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer3
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')2
- CWE-352 Cross-Site Request Forgery (CSRF)2
- CWE-254 7PK - Security Features1
- CWE-264 Permissions, Privileges, and Access Controls1
- CWE-284 Improper Access Control1
The weakness classes this vendor ships most often: where to look.
CWEAll records
16 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
40Plan | CVE-2015-7792No exploit | Corega CG-WLBARGS devices allow remote attackers to perform administrative operations via unspecified vectors.corega · cg-wlbargs firmware · CWE-264 | Critical9.8 | — | 2.8% | Dec 30, 2015 |
35Monitor | CVE-2016-7809No exploit | Cross-site request forgery (CSRF) vulnerability in Corega CG-WLR300NX firmware Ver.corega · cg-wlr300nx firmware · CWE-352 | High8.8 | — | 0.9% | Jun 9, 2017 |
35Monitor | CVE-2016-7811No exploit | Corega CG-WLR300NX firmware Ver.corega · cg-wlr300nx firmware · CWE-284 | High8.8 | — | 0.9% | Jun 9, 2017 |
35Monitor | CVE-2017-10852No exploit | Buffer overflow in Corega CG-WGR1200 firmware 2.20 and earlier allows an attacker to execute arbitrary code via unspecified vectors.corega · cg-wgr 1200 firmware · CWE-119 | High8.8 | — | 0.8% | Mar 9, 2018 |
35Monitor | CVE-2017-10853No exploit | Buffer overflow in Corega CG-WGR1200 firmware 2.20 and earlier allows an attacker to execute arbitrary commands via unspecified vectors.corega · cg-wgr 1200 firmware · CWE-119 | High8.8 | — | 0.8% | Mar 9, 2018 |
35Monitor | CVE-2016-1158No exploit | Cross-site request forgery (CSRF) vulnerability on Corega CG-WLBARGMH and CG-WLBARGNL devices allows remote attackers to hijack the authenticorega · cg-wlbargmh · CWE-352 | High8.8 | — | 0.6% | Mar 3, 2016 |
35Monitor | CVE-2017-10854No exploit | Corega CG-WGR1200 firmware 2.20 and earlier allows an attacker to bypass authentication and change the login password via unspecified vectorcorega · cg-wgr 1200 firmware · CWE-306 | High8.8 | — | 0.6% | Mar 9, 2018 |
32Monitor | CVE-2016-4822No exploit | Corega CG-WLBARGL devices allow remote authenticated users to execute arbitrary commands via unspecified vectors.corega · cg-wlbargl firmware · CWE-77 | High8.0 | — | 1.1% | Jun 25, 2016 |
31Monitor | CVE-2016-4823No exploit | Corega CG-WLBARAGM devices allow remote attackers to cause a denial of service (reboot) via unspecified vectors.corega · cg-wlbargmh | High7.5 | — | 1.9% | Jun 25, 2016 |
27Monitor | CVE-2017-10814No exploit | Buffer overflow in CG-WLR300NM Firmware version 1.90 and earlier allows an attacker to execute arbitrary code via unspecified vectors.corega · wlr 300 nm firmware · CWE-119 | Medium6.8 | — | 0.8% | Sep 15, 2017 |
27Monitor | CVE-2017-10813No exploit | CG-WLR300NM Firmware version 1.90 and earlier allows an attacker to execute arbitrary OS commands via unspecified vectors.corega · wlr 300 nm firmware · CWE-78 | Medium6.8 | — | 0.7% | Sep 15, 2017 |
24Monitor | CVE-2016-7808No exploit | Cross-site scripting vulnerability in Corega CG-WLBARGMH and CG-WLBARGNL allows remote attackers to inject arbitrary web script or HTML via corega · cg-wlbaragm firmware · CWE-79 | Medium6.1 | — | 1.2% | Jun 9, 2017 |
23Monitor | CVE-2015-7794No exploit | Corega CG-WLNCM4G devices provide an open DNS resolver, which allows remote attackers to cause a denial of service (traffic amplification) vcorega · cg-wlncm4g firmware · CWE-20 | Medium5.8 | — | 1.6% | Dec 30, 2015 |
23Monitor | CVE-2015-7793No exploit | Corega CG-WLBARAGM devices provide an open proxy service, which allows remote attackers to trigger outbound network traffic via unspecified corega · cg-wlbaragm firmware · CWE-17 | Medium5.8 | — | 1.6% | Dec 30, 2015 |
21Monitor | CVE-2016-4824No exploit | The Wi-Fi Protected Setup (WPS) implementation on Corega CG-WLR300GNV and CG-WLR300GNV-W devices does not restrict the number of PIN authentcorega · cg-wlr300gnv · CWE-254 | Medium5.3 | — | 1.4% | Jun 25, 2016 |
19Monitor | CVE-2016-7810No exploit | Cross-site scripting vulnerability in Corega CG-WLR300NX firmware Ver.corega · cg-wlr300nx firmware · CWE-79 | Medium4.8 | — | 0.8% | Jun 9, 2017 |
- CVE-2015-779240Plan
Corega CG-WLBARGS devices allow remote attackers to perform administrative operations via unspecified vectors.
CriticalCVSS 9.8No exploitEPSS 3%corega · cg-wlbargs firmwareDec 30, 2015
- CVE-2016-780935Monitor
Cross-site request forgery (CSRF) vulnerability in Corega CG-WLR300NX firmware Ver.
HighCVSS 8.8No exploitEPSS 1%corega · cg-wlr300nx firmwareJun 9, 2017
- CVE-2016-781135Monitor
Corega CG-WLR300NX firmware Ver.
HighCVSS 8.8No exploitEPSS 1%corega · cg-wlr300nx firmwareJun 9, 2017
- CVE-2017-1085235Monitor
Buffer overflow in Corega CG-WGR1200 firmware 2.20 and earlier allows an attacker to execute arbitrary code via unspecified vectors.
HighCVSS 8.8No exploitEPSS 1%corega · cg-wgr 1200 firmwareMar 9, 2018
- CVE-2017-1085335Monitor
Buffer overflow in Corega CG-WGR1200 firmware 2.20 and earlier allows an attacker to execute arbitrary commands via unspecified vectors.
HighCVSS 8.8No exploitEPSS 1%corega · cg-wgr 1200 firmwareMar 9, 2018
- CVE-2016-115835Monitor
Cross-site request forgery (CSRF) vulnerability on Corega CG-WLBARGMH and CG-WLBARGNL devices allows remote attackers to hijack the authenti
HighCVSS 8.8No exploitEPSS 1%corega · cg-wlbargmhMar 3, 2016
- CVE-2017-1085435Monitor
Corega CG-WGR1200 firmware 2.20 and earlier allows an attacker to bypass authentication and change the login password via unspecified vector
HighCVSS 8.8No exploitEPSS 1%corega · cg-wgr 1200 firmwareMar 9, 2018
- CVE-2016-482232Monitor
Corega CG-WLBARGL devices allow remote authenticated users to execute arbitrary commands via unspecified vectors.
HighCVSS 8.0No exploitEPSS 1%corega · cg-wlbargl firmwareJun 25, 2016
- CVE-2016-482331Monitor
Corega CG-WLBARAGM devices allow remote attackers to cause a denial of service (reboot) via unspecified vectors.
HighCVSS 7.5No exploitEPSS 2%corega · cg-wlbargmhJun 25, 2016
- CVE-2017-1081427Monitor
Buffer overflow in CG-WLR300NM Firmware version 1.90 and earlier allows an attacker to execute arbitrary code via unspecified vectors.
MediumCVSS 6.8No exploitEPSS 1%corega · wlr 300 nm firmwareSep 15, 2017
- CVE-2017-1081327Monitor
CG-WLR300NM Firmware version 1.90 and earlier allows an attacker to execute arbitrary OS commands via unspecified vectors.
MediumCVSS 6.8No exploitEPSS 1%corega · wlr 300 nm firmwareSep 15, 2017
- CVE-2016-780824Monitor
Cross-site scripting vulnerability in Corega CG-WLBARGMH and CG-WLBARGNL allows remote attackers to inject arbitrary web script or HTML via
MediumCVSS 6.1No exploitEPSS 1%corega · cg-wlbaragm firmwareJun 9, 2017
- CVE-2015-779423Monitor
Corega CG-WLNCM4G devices provide an open DNS resolver, which allows remote attackers to cause a denial of service (traffic amplification) v
MediumCVSS 5.8No exploitEPSS 2%corega · cg-wlncm4g firmwareDec 30, 2015
- CVE-2015-779323Monitor
Corega CG-WLBARAGM devices provide an open proxy service, which allows remote attackers to trigger outbound network traffic via unspecified
MediumCVSS 5.8No exploitEPSS 2%corega · cg-wlbaragm firmwareDec 30, 2015
- CVE-2016-482421Monitor
The Wi-Fi Protected Setup (WPS) implementation on Corega CG-WLR300GNV and CG-WLR300GNV-W devices does not restrict the number of PIN authent
MediumCVSS 5.3No exploitEPSS 1%corega · cg-wlr300gnvJun 25, 2016
- CVE-2016-781019Monitor
Cross-site scripting vulnerability in Corega CG-WLR300NX firmware Ver.
MediumCVSS 4.8No exploitEPSS 1%corega · cg-wlr300nx firmwareJun 9, 2017