Juplink records
7 published records for vendor juplink.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-77 Improper Neutralization of Special Elements used in a Command ('Command Injection')2
- CWE-121 Stack-based Buffer Overflow1
- CWE-210 Self-generated Error Message Containing Sensitive Information1
- CWE-259 Use of Hard-coded Password1
- CWE-276 Incorrect Default Permissions1
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')1
The weakness classes this vendor ships most often: where to look.
CWEAll records
7 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
39Monitor | CVE-2023-41030No exploit | Juplink RX4-1500 Hard-coded Credential Vulnerabilityjuplink · rx4-1500 firmware · CWE-259 | Critical9.8 | — | 0.7% | Sep 18, 2023 |
36Monitor | CVE-2023-41029No exploit | Juplink RX4-1500 Command Injection Vulnerabilityjuplink · rx4-1500 firmware · CWE-77 | High8.8 | — | 2.7% | Sep 22, 2023 |
36Monitor | CVE-2023-41031No exploit | Juplink RX4-1500 homemng.htm Command Injection Vulnerabilityjuplink · rx4-1500 firmware · CWE-77 | High8.8 | — | 2.2% | Sep 22, 2023 |
35Monitor | CVE-2023-41027No exploit | Juplink RX4-1500 Credential Disclosure Vulnerabilityjuplink · rx4-1500 firmware · CWE-210 | High8.8 | — | 0.9% | Sep 22, 2023 |
35Monitor | CVE-2023-41028No exploit | Juplink RX4-1500 Stack-based Buffer Overflow Vulnerabilityjuplink · rx4-1500 firmware · CWE-121 | High8.8 | — | 0.9% | Aug 23, 2023 |
26Monitor | CVE-2020-8797No exploit | Juplink RX4-1500 v1.0.3 allows remote attackers to gain root access to the Linux subsystem via an unsanitized exec call (aka Command Line Injuplink · rx4-1500 firmware · CWE-78 | Medium6.7 | — | 0.9% | Apr 23, 2020 |
22Monitor | CVE-2020-8798No exploit | httpd in Juplink RX4-1500 v1.0.3-v1.0.5 allows remote attackers to change or access router settings by connecting to the unauthenticated setjuplink · rx4-1500 firmware · CWE-276 | Medium5.5 | — | 0.4% | Apr 23, 2020 |
- CVE-2023-4103039Monitor
Juplink RX4-1500 Hard-coded Credential Vulnerability
CriticalCVSS 9.8No exploitEPSS 1%juplink · rx4-1500 firmwareSep 18, 2023
- CVE-2023-4102936Monitor
Juplink RX4-1500 Command Injection Vulnerability
HighCVSS 8.8No exploitEPSS 3%juplink · rx4-1500 firmwareSep 22, 2023
- CVE-2023-4103136Monitor
Juplink RX4-1500 homemng.htm Command Injection Vulnerability
HighCVSS 8.8No exploitEPSS 2%juplink · rx4-1500 firmwareSep 22, 2023
- CVE-2023-4102735Monitor
Juplink RX4-1500 Credential Disclosure Vulnerability
HighCVSS 8.8No exploitEPSS 1%juplink · rx4-1500 firmwareSep 22, 2023
- CVE-2023-4102835Monitor
Juplink RX4-1500 Stack-based Buffer Overflow Vulnerability
HighCVSS 8.8No exploitEPSS 1%juplink · rx4-1500 firmwareAug 23, 2023
- CVE-2020-879726Monitor
Juplink RX4-1500 v1.0.3 allows remote attackers to gain root access to the Linux subsystem via an unsanitized exec call (aka Command Line In
MediumCVSS 6.7No exploitEPSS 1%juplink · rx4-1500 firmwareApr 23, 2020
- CVE-2020-879822Monitor
httpd in Juplink RX4-1500 v1.0.3-v1.0.5 allows remote attackers to change or access router settings by connecting to the unauthenticated set
MediumCVSS 5.5No exploitEPSS 0%juplink · rx4-1500 firmwareApr 23, 2020