Skip to content
Noroxi

evenroute records

6 published records for vendor evenroute.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
1
With a fix record
0%
Median publish → KEV
No record has entered KEV

All records

6 records
  • In IQrouter through 3.3.1, remote attackers can control the device (restart network, reboot, upgrade, reset) because of Incorrect Access Con

    CriticalCVSS 9.8No exploitEPSS 3%

    evenroute · iqrouter firmwareApr 21, 2020

  • IQrouter through 3.3.1, when unconfigured, has multiple remote code execution vulnerabilities in the web-panel because of Bash Shell Metacha

    CriticalCVSS 9.8No exploitEPSS 3%

    evenroute · iqrouter firmwareApr 21, 2020

  • In IQrouter through 3.3.1, the Lua function reset_password in the web-panel allows remote attackers to change the root password arbitrarily.

    CriticalCVSS 9.8No exploitEPSS 3%

    evenroute · iqrouter firmwareApr 21, 2020

  • In IQrouter through 3.3.1, there is a root user without a password, which allows attackers to gain full remote access via SSH.

    CriticalCVSS 9.8No exploitEPSS 2%

    evenroute · iqrouter firmwareApr 21, 2020

  • In the web-panel in IQrouter through 3.3.1, remote attackers can read system logs because of Incorrect Access Control.

    HighCVSS 7.5No exploitEPSS 3%

    evenroute · iqrouter firmwareApr 21, 2020

  • In IQrouter through 3.3.1, the Lua function diag_set_password in the web-panel allows remote attackers to change the root password arbitrari

    HighCVSS 7.5No exploitEPSS 2%

    evenroute · iqrouter firmwareApr 21, 2020