IP-COM records
21 published records for vendor ip-com.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 5
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-120 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')13
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')4
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer1
- CWE-77 Improper Neutralization of Special Elements used in a Command ('Command Injection')1
The weakness classes this vendor ships most often: where to look.
CWEAll records
21 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
45Plan | CVE-2022-45711No exploit | IP-COM M50 V15.11.0.33(10768) was discovered to contain a command injection vulnerability via the hostname parameter in the formSetNetCheckTip-com · m50 firmware · CWE-78 | Critical9.8 | — | 20.2% | Dec 23, 2022 |
41Plan | CVE-2022-45005No exploit | IP-COM EW9 V15.11.0.14(9732) was discovered to contain a command injection vulnerability in the cmd_get_ping_output function.ip-com · ew9 firmware · CWE-78 | Critical9.8 | — | 5.4% | Dec 13, 2022 |
41Plan | CVE-2022-43367No exploit | IP-COM EW9 V15.11.0.14(9732) was discovered to contain a command injection vulnerability in the formSetDebugCfg function.ip-com · ew9 firmware · CWE-77 | Critical9.8 | — | 5.2% | Oct 27, 2022 |
40Plan | CVE-2022-45709No exploit | IP-COM M50 V15.11.0.33(10768) was discovered to contain multiple command injection vulnerabilities via the pEnable, pLevel, and pModule paraip-com · m50 firmware · CWE-78 | Critical9.8 | — | 4.3% | Dec 23, 2022 |
40Plan | CVE-2022-45717No exploit | IP-COM M50 V15.11.0.33(10768) was discovered to contain a command injection vulnerability via the usbPartitionName parameter in the formSetUip-com · m50 firmware · CWE-78 | Critical9.8 | — | 4.3% | Dec 23, 2022 |
39Monitor | CVE-2022-45708No exploit | IP-COM M50 V15.11.0.33(10768) was discovered to contain a buffer overflow via the sPortMapIndex parameter in the formDelPortMapping functionip-com · m50 firmware · CWE-120 | Critical9.8 | — | 1.1% | Dec 23, 2022 |
39Monitor | CVE-2022-45710No exploit | IP-COM M50 V15.11.0.33(10768) was discovered to contain multiple buffer overflows via the pEnable, pLevel, and pModule parameters in the forip-com · m50 firmware · CWE-120 | Critical9.8 | — | 1.1% | Dec 23, 2022 |
39Monitor | CVE-2022-45712No exploit | IP-COM M50 V15.11.0.33(10768) was discovered to contain a buffer overflow via the rules parameter in the formAddDnsForward function.ip-com · m50 firmware · CWE-120 | Critical9.8 | — | 1.1% | Dec 23, 2022 |
39Monitor | CVE-2022-45714No exploit | IP-COM M50 V15.11.0.33(10768) was discovered to contain a buffer overflow via the indexSet parameter in the formQOSRuleDel function.ip-com · m50 firmware · CWE-120 | Critical9.8 | — | 1.1% | Dec 23, 2022 |
39Monitor | CVE-2022-45715No exploit | IP-COM M50 V15.11.0.33(10768) was discovered to contain multiple buffer overflows via the pLanPortRange and pWanPortRange parameters in the ip-com · m50 firmware · CWE-120 | Critical9.8 | — | 1.1% | Dec 23, 2022 |
39Monitor | CVE-2022-45716No exploit | IP-COM M50 V15.11.0.33(10768) was discovered to contain a buffer overflow via the indexSet parameter in the formIPMacBindDel function.ip-com · m50 firmware · CWE-120 | Critical9.8 | — | 1.1% | Dec 23, 2022 |
39Monitor | CVE-2022-45719No exploit | IP-COM M50 V15.11.0.33(10768) was discovered to contain a buffer overflow via the gotoUrl parameter in the formPortalAuth function.ip-com · m50 firmware · CWE-120 | Critical9.8 | — | 1.1% | Dec 23, 2022 |
39Monitor | CVE-2022-45718No exploit | IP-COM M50 V15.11.0.33(10768) was discovered to contain a buffer overflow via the rules parameter in the formIPMacBindAdd function.ip-com · m50 firmware · CWE-120 | Critical9.8 | — | 1.1% | Dec 23, 2022 |
39Monitor | CVE-2022-45721No exploit | IP-COM M50 V15.11.0.33(10768) was discovered to contain a buffer overflow via the picName parameter in the formDelWewifiPic function.ip-com · m50 firmware · CWE-120 | Critical9.8 | — | 1.1% | Dec 23, 2022 |
39Monitor | CVE-2022-45720No exploit | IP-COM M50 V15.11.0.33(10768) was discovered to contain multiple buffer overflows via the ip, mac, and remark parameters in the formIPMacBinip-com · m50 firmware · CWE-120 | Critical9.8 | — | 1.1% | Dec 23, 2022 |
39Monitor | CVE-2022-45706No exploit | IP-COM M50 V15.11.0.33(10768) was discovered to contain a buffer overflow via the hostname parameter in the formSetNetCheckTools function.ip-com · m50 firmware · CWE-120 | Critical9.8 | — | 1.1% | Dec 23, 2022 |
39Monitor | CVE-2022-45707No exploit | IP-COM M50 V15.11.0.33(10768) was discovered to contain a buffer overflow via the rules parameter in the formAddDnsHijack function.ip-com · m50 firmware · CWE-120 | Critical9.8 | — | 1.1% | Dec 23, 2022 |
36Monitor | CVE-2026-2017No exploit | IP-COM W30AP POST Request wx3auth R7WebsSecurityHandler stack-based overflowip-com · w30ap firmware · CWE-119 | High8.9 | — | 4.6% | Feb 6, 2026 |
30Monitor | CVE-2022-43365No exploit | IP-COM EW9 V15.11.0.14(9732) was discovered to contain a buffer overflow in the formSetDebugCfg function.ip-com · ew9 firmware · CWE-120 | High7.5 | — | 0.9% | Oct 27, 2022 |
30Monitor | CVE-2022-43366No exploit | IP-COM EW9 V15.11.0.14(9732) allows unauthenticated attackers to access sensitive information via the checkLoginUser, ate, telnet, version, ip-com · ew9 firmware | High7.5 | — | 0.8% | Oct 27, 2022 |
30Monitor | CVE-2022-43364No exploit | An access control issue in the password reset page of IP-COM EW9 V15.11.0.14(9732) allows unauthenticated attackers to arbitrarily change thip-com · ew9 firmware | High7.5 | — | 0.7% | Oct 27, 2022 |
- CVE-2022-4571145Plan
IP-COM M50 V15.11.0.33(10768) was discovered to contain a command injection vulnerability via the hostname parameter in the formSetNetCheckT
CriticalCVSS 9.8No exploitEPSS 20%ip-com · m50 firmwareDec 23, 2022
- CVE-2022-4500541Plan
IP-COM EW9 V15.11.0.14(9732) was discovered to contain a command injection vulnerability in the cmd_get_ping_output function.
CriticalCVSS 9.8No exploitEPSS 5%ip-com · ew9 firmwareDec 13, 2022
- CVE-2022-4336741Plan
IP-COM EW9 V15.11.0.14(9732) was discovered to contain a command injection vulnerability in the formSetDebugCfg function.
CriticalCVSS 9.8No exploitEPSS 5%ip-com · ew9 firmwareOct 27, 2022
- CVE-2022-4570940Plan
IP-COM M50 V15.11.0.33(10768) was discovered to contain multiple command injection vulnerabilities via the pEnable, pLevel, and pModule para
CriticalCVSS 9.8No exploitEPSS 4%ip-com · m50 firmwareDec 23, 2022
- CVE-2022-4571740Plan
IP-COM M50 V15.11.0.33(10768) was discovered to contain a command injection vulnerability via the usbPartitionName parameter in the formSetU
CriticalCVSS 9.8No exploitEPSS 4%ip-com · m50 firmwareDec 23, 2022
- CVE-2022-4570839Monitor
IP-COM M50 V15.11.0.33(10768) was discovered to contain a buffer overflow via the sPortMapIndex parameter in the formDelPortMapping function
CriticalCVSS 9.8No exploitEPSS 1%ip-com · m50 firmwareDec 23, 2022
- CVE-2022-4571039Monitor
IP-COM M50 V15.11.0.33(10768) was discovered to contain multiple buffer overflows via the pEnable, pLevel, and pModule parameters in the for
CriticalCVSS 9.8No exploitEPSS 1%ip-com · m50 firmwareDec 23, 2022
- CVE-2022-4571239Monitor
IP-COM M50 V15.11.0.33(10768) was discovered to contain a buffer overflow via the rules parameter in the formAddDnsForward function.
CriticalCVSS 9.8No exploitEPSS 1%ip-com · m50 firmwareDec 23, 2022
- CVE-2022-4571439Monitor
IP-COM M50 V15.11.0.33(10768) was discovered to contain a buffer overflow via the indexSet parameter in the formQOSRuleDel function.
CriticalCVSS 9.8No exploitEPSS 1%ip-com · m50 firmwareDec 23, 2022
- CVE-2022-4571539Monitor
IP-COM M50 V15.11.0.33(10768) was discovered to contain multiple buffer overflows via the pLanPortRange and pWanPortRange parameters in the
CriticalCVSS 9.8No exploitEPSS 1%ip-com · m50 firmwareDec 23, 2022
- CVE-2022-4571639Monitor
IP-COM M50 V15.11.0.33(10768) was discovered to contain a buffer overflow via the indexSet parameter in the formIPMacBindDel function.
CriticalCVSS 9.8No exploitEPSS 1%ip-com · m50 firmwareDec 23, 2022
- CVE-2022-4571939Monitor
IP-COM M50 V15.11.0.33(10768) was discovered to contain a buffer overflow via the gotoUrl parameter in the formPortalAuth function.
CriticalCVSS 9.8No exploitEPSS 1%ip-com · m50 firmwareDec 23, 2022
- CVE-2022-4571839Monitor
IP-COM M50 V15.11.0.33(10768) was discovered to contain a buffer overflow via the rules parameter in the formIPMacBindAdd function.
CriticalCVSS 9.8No exploitEPSS 1%ip-com · m50 firmwareDec 23, 2022
- CVE-2022-4572139Monitor
IP-COM M50 V15.11.0.33(10768) was discovered to contain a buffer overflow via the picName parameter in the formDelWewifiPic function.
CriticalCVSS 9.8No exploitEPSS 1%ip-com · m50 firmwareDec 23, 2022
- CVE-2022-4572039Monitor
IP-COM M50 V15.11.0.33(10768) was discovered to contain multiple buffer overflows via the ip, mac, and remark parameters in the formIPMacBin
CriticalCVSS 9.8No exploitEPSS 1%ip-com · m50 firmwareDec 23, 2022
- CVE-2022-4570639Monitor
IP-COM M50 V15.11.0.33(10768) was discovered to contain a buffer overflow via the hostname parameter in the formSetNetCheckTools function.
CriticalCVSS 9.8No exploitEPSS 1%ip-com · m50 firmwareDec 23, 2022
- CVE-2022-4570739Monitor
IP-COM M50 V15.11.0.33(10768) was discovered to contain a buffer overflow via the rules parameter in the formAddDnsHijack function.
CriticalCVSS 9.8No exploitEPSS 1%ip-com · m50 firmwareDec 23, 2022
- CVE-2026-201736Monitor
IP-COM W30AP POST Request wx3auth R7WebsSecurityHandler stack-based overflow
HighCVSS 8.9No exploitEPSS 5%ip-com · w30ap firmwareFeb 6, 2026
- CVE-2022-4336530Monitor
IP-COM EW9 V15.11.0.14(9732) was discovered to contain a buffer overflow in the formSetDebugCfg function.
HighCVSS 7.5No exploitEPSS 1%ip-com · ew9 firmwareOct 27, 2022
- CVE-2022-4336630Monitor
IP-COM EW9 V15.11.0.14(9732) allows unauthenticated attackers to access sensitive information via the checkLoginUser, ate, telnet, version,
HighCVSS 7.5No exploitEPSS 1%ip-com · ew9 firmwareOct 27, 2022
- CVE-2022-4336430Monitor
An access control issue in the password reset page of IP-COM EW9 V15.11.0.14(9732) allows unauthenticated attackers to arbitrarily change th
HighCVSS 7.5No exploitEPSS 1%ip-com · ew9 firmwareOct 27, 2022