Digisol records
10 published records for vendor digisol.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')4
- CWE-1191 On-Chip Debug and Test Interface With Improper Access Control1
- CWE-20 Improper Input Validation1
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer1
- CWE-352 Cross-Site Request Forgery (CSRF)1
- CWE-565 Reliance on Cookies without Validation and Integrity Checking1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
10 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
42Plan | CVE-2018-12706Proof of concept | DIGISOL DG-BR4000NG devices have a Buffer Overflow via a long Authorization HTTP header.digisol · dg-br4000ng firmware · CWE-119 | Critical9.8 | — | 9.9% | Jun 24, 2018 |
36Monitor | CVE-2017-6896Proof of concept | Privilege escalation vulnerability on the DIGISOL DG-HR1400 1.00.02 wireless router enables an attacker to escalate from user privilege to adigisol · dg-hr1400 router firmware · CWE-565 | High8.8 | — | 3.7% | Mar 14, 2017 |
36Monitor | CVE-2024-2257Proof of concept | Password Policy Bypass Vulnerability in Digisol Routerdigisol · digisol router dg-gr1321 · CWE-20 | Critical9.1 | — | 1.0% | May 14, 2024 |
35Monitor | CVE-2017-6127No exploit | Multiple cross-site request forgery (CSRF) vulnerabilities in the access portal on the DIGISOL DG-HR1400 Wireless Router with firmware 1.00.digisol · dg-hr1400 firmware · CWE-352 | High8.8 | — | 0.8% | Feb 21, 2017 |
27Monitor | CVE-2024-4231Proof of concept | Incorrect Access Control Vulnerability in Digisol Routerdigisol · digisol router dg-gr1321 · CWE-1191 | Medium6.8 | — | 0.6% | May 14, 2024 |
25Monitor | CVE-2018-12705Proof of concept | DIGISOL DG-BR4000NG devices have XSS via the SSID (it is validated only on the client side).digisol · dg-br4000ng firmware · CWE-79 | Medium6.1 | — | 2.3% | Jun 24, 2018 |
24Monitor | CVE-2020-35262Proof of concept | Cross Site Scripting (XSS) vulnerability in Digisol DG-HR3400 can be exploited via the NTP server name in Time and date module and "Keyword"digisol · dg-hr3400 firmware · CWE-79 | Medium6.1 | — | 0.9% | Jan 6, 2021 |
24Monitor | CVE-2018-12715No exploit | DIGISOL DG-HR3400 devices have XSS via a modified SSID when the apssid value is unchanged.digisol · dg-hr3400 firmware · CWE-79 | Medium6.1 | — | 0.9% | Jul 3, 2019 |
24Monitor | CVE-2018-14027No exploit | Digisol Wireless Wifi Home Router HR-3300 allows XSS via the userid or password parameter to the admin login page.digisol · dg-hr-3300 firmware · CWE-79 | Medium6.1 | — | 0.8% | Jul 5, 2019 |
21Monitor | CVE-2024-4232Proof of concept | Password Storage in Plaintext Vulnerability in Digisol Routerdigisol · digisol router dg-gr1321 · CWE-256 | Medium5.4 | — | 0.3% | May 14, 2024 |
- CVE-2018-1270642Plan
DIGISOL DG-BR4000NG devices have a Buffer Overflow via a long Authorization HTTP header.
CriticalCVSS 9.8Proof of conceptEPSS 10%digisol · dg-br4000ng firmwareJun 24, 2018
- CVE-2017-689636Monitor
Privilege escalation vulnerability on the DIGISOL DG-HR1400 1.00.02 wireless router enables an attacker to escalate from user privilege to a
HighCVSS 8.8Proof of conceptEPSS 4%digisol · dg-hr1400 router firmwareMar 14, 2017
- CVE-2024-225736Monitor
Password Policy Bypass Vulnerability in Digisol Router
CriticalCVSS 9.1Proof of conceptEPSS 1%digisol · digisol router dg-gr1321May 14, 2024
- CVE-2017-612735Monitor
Multiple cross-site request forgery (CSRF) vulnerabilities in the access portal on the DIGISOL DG-HR1400 Wireless Router with firmware 1.00.
HighCVSS 8.8No exploitEPSS 1%digisol · dg-hr1400 firmwareFeb 21, 2017
- CVE-2024-423127Monitor
Incorrect Access Control Vulnerability in Digisol Router
MediumCVSS 6.8Proof of conceptEPSS 1%digisol · digisol router dg-gr1321May 14, 2024
- CVE-2018-1270525Monitor
DIGISOL DG-BR4000NG devices have XSS via the SSID (it is validated only on the client side).
MediumCVSS 6.1Proof of conceptEPSS 2%digisol · dg-br4000ng firmwareJun 24, 2018
- CVE-2020-3526224Monitor
Cross Site Scripting (XSS) vulnerability in Digisol DG-HR3400 can be exploited via the NTP server name in Time and date module and "Keyword"
MediumCVSS 6.1Proof of conceptEPSS 1%digisol · dg-hr3400 firmwareJan 6, 2021
- CVE-2018-1271524Monitor
DIGISOL DG-HR3400 devices have XSS via a modified SSID when the apssid value is unchanged.
MediumCVSS 6.1No exploitEPSS 1%digisol · dg-hr3400 firmwareJul 3, 2019
- CVE-2018-1402724Monitor
Digisol Wireless Wifi Home Router HR-3300 allows XSS via the userid or password parameter to the admin login page.
MediumCVSS 6.1No exploitEPSS 1%digisol · dg-hr-3300 firmwareJul 5, 2019
- CVE-2024-423221Monitor
Password Storage in Plaintext Vulnerability in Digisol Router
MediumCVSS 5.4Proof of conceptEPSS 0%digisol · digisol router dg-gr1321May 14, 2024