evenroute records
6 published records for vendor evenroute.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 1
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-287 Improper Authentication2
- CWE-521 Weak Password Requirements1
- CWE-532 Insertion of Sensitive Information into Log File1
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')1
- CWE-862 Missing Authorization1
The weakness classes this vendor ships most often: where to look.
CWEAll records
6 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
40Plan | CVE-2020-11967No exploit | In IQrouter through 3.3.1, remote attackers can control the device (restart network, reboot, upgrade, reset) because of Incorrect Access Conevenroute · iqrouter firmware · CWE-862 | Critical9.8 | — | 3.3% | Apr 21, 2020 |
40Plan | CVE-2020-11963No exploit | IQrouter through 3.3.1, when unconfigured, has multiple remote code execution vulnerabilities in the web-panel because of Bash Shell Metachaevenroute · iqrouter firmware · CWE-78 | Critical9.8 | — | 3.2% | Apr 21, 2020 |
40Plan | CVE-2020-11966No exploit | In IQrouter through 3.3.1, the Lua function reset_password in the web-panel allows remote attackers to change the root password arbitrarily.evenroute · iqrouter firmware · CWE-521 | Critical9.8 | — | 3.1% | Apr 21, 2020 |
40Plan | CVE-2020-11965No exploit | In IQrouter through 3.3.1, there is a root user without a password, which allows attackers to gain full remote access via SSH.evenroute · iqrouter firmware · CWE-287 | Critical9.8 | — | 2.1% | Apr 21, 2020 |
31Monitor | CVE-2020-11968No exploit | In the web-panel in IQrouter through 3.3.1, remote attackers can read system logs because of Incorrect Access Control.evenroute · iqrouter firmware · CWE-532 | High7.5 | — | 2.7% | Apr 21, 2020 |
31Monitor | CVE-2020-11964No exploit | In IQrouter through 3.3.1, the Lua function diag_set_password in the web-panel allows remote attackers to change the root password arbitrarievenroute · iqrouter firmware · CWE-287 | High7.5 | — | 2.3% | Apr 21, 2020 |
- CVE-2020-1196740Plan
In IQrouter through 3.3.1, remote attackers can control the device (restart network, reboot, upgrade, reset) because of Incorrect Access Con
CriticalCVSS 9.8No exploitEPSS 3%evenroute · iqrouter firmwareApr 21, 2020
- CVE-2020-1196340Plan
IQrouter through 3.3.1, when unconfigured, has multiple remote code execution vulnerabilities in the web-panel because of Bash Shell Metacha
CriticalCVSS 9.8No exploitEPSS 3%evenroute · iqrouter firmwareApr 21, 2020
- CVE-2020-1196640Plan
In IQrouter through 3.3.1, the Lua function reset_password in the web-panel allows remote attackers to change the root password arbitrarily.
CriticalCVSS 9.8No exploitEPSS 3%evenroute · iqrouter firmwareApr 21, 2020
- CVE-2020-1196540Plan
In IQrouter through 3.3.1, there is a root user without a password, which allows attackers to gain full remote access via SSH.
CriticalCVSS 9.8No exploitEPSS 2%evenroute · iqrouter firmwareApr 21, 2020
- CVE-2020-1196831Monitor
In the web-panel in IQrouter through 3.3.1, remote attackers can read system logs because of Incorrect Access Control.
HighCVSS 7.5No exploitEPSS 3%evenroute · iqrouter firmwareApr 21, 2020
- CVE-2020-1196431Monitor
In IQrouter through 3.3.1, the Lua function diag_set_password in the web-panel allows remote attackers to change the root password arbitrari
HighCVSS 7.5No exploitEPSS 2%evenroute · iqrouter firmwareApr 21, 2020