MitraStar records
6 published records for vendor mitrastar.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')3
- CWE-276 Incorrect Default Permissions1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
6 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
40Plan | CVE-2017-16523No exploit | MitraStar GPT-2541GNAC (HGU) 1.00(VNJ0)b1 and DSL-100HN-T1 ES_113WJY0b16 devices have a zyad1234 password for the zyad1234 account, which ismitrastar · gpt-2541gnac firmware | Critical9.8 | — | 3.8% | Nov 3, 2017 |
39Monitor | CVE-2021-42165Proof of concept | MitraStar GPT-2541GNAC-N1 (HGU) 100VNZ0b33 devices allow remote authenticated users to obtain root access by executing command "deviceinfo smitrastar · gpt-2541gnac-n1 firmware · CWE-78 | High8.8 | — | 14.1% | May 3, 2022 |
36Monitor | CVE-2017-16522No exploit | MitraStar GPT-2541GNAC (HGU) 1.00(VNJ0)b1 and DSL-100HN-T1 ES_113WJY0b16 devices allow remote authenticated users to obtain root access by smitrastar · gpt-2541gnac firmware · CWE-276 | High8.8 | — | 2.6% | Nov 3, 2017 |
35Monitor | CVE-2023-33381Proof of concept | A command injection vulnerability was found in the ping functionality of the MitraStar GPT-2741GNAC router (firmware version AR_g5.8_110WVN0mitrastar · gpt-2741gnac firmware · CWE-78 | High7.2 | — | 22.4% | Jun 6, 2023 |
35Monitor | CVE-2023-30065No exploit | MitraStar GPT-2741GNAC-N2 with firmware BR_g5.9_1.11(WVK.0)b32 was discovered to contain a remote code execution (RCE) vulnerability in the mitrastar · gpt-2741gnac-n2 firmware | High8.8 | — | 1.3% | May 5, 2023 |
27Monitor | CVE-2024-9977No exploit | MitraStar GPT-2541GNAC Firewall Settings Page settings-firewall.cgi os command injectionmitrastar · gpt-2541gnac · CWE-78 | Medium5.1 | — | 22.9% | Oct 15, 2024 |
- CVE-2017-1652340Plan
MitraStar GPT-2541GNAC (HGU) 1.00(VNJ0)b1 and DSL-100HN-T1 ES_113WJY0b16 devices have a zyad1234 password for the zyad1234 account, which is
CriticalCVSS 9.8No exploitEPSS 4%mitrastar · gpt-2541gnac firmwareNov 3, 2017
- CVE-2021-4216539Monitor
MitraStar GPT-2541GNAC-N1 (HGU) 100VNZ0b33 devices allow remote authenticated users to obtain root access by executing command "deviceinfo s
HighCVSS 8.8Proof of conceptEPSS 14%mitrastar · gpt-2541gnac-n1 firmwareMay 3, 2022
- CVE-2017-1652236Monitor
MitraStar GPT-2541GNAC (HGU) 1.00(VNJ0)b1 and DSL-100HN-T1 ES_113WJY0b16 devices allow remote authenticated users to obtain root access by s
HighCVSS 8.8No exploitEPSS 3%mitrastar · gpt-2541gnac firmwareNov 3, 2017
- CVE-2023-3338135Monitor
A command injection vulnerability was found in the ping functionality of the MitraStar GPT-2741GNAC router (firmware version AR_g5.8_110WVN0
HighCVSS 7.2Proof of conceptEPSS 22%mitrastar · gpt-2741gnac firmwareJun 6, 2023
- CVE-2023-3006535Monitor
MitraStar GPT-2741GNAC-N2 with firmware BR_g5.9_1.11(WVK.0)b32 was discovered to contain a remote code execution (RCE) vulnerability in the
HighCVSS 8.8No exploitEPSS 1%mitrastar · gpt-2741gnac-n2 firmwareMay 5, 2023
- CVE-2024-997727Monitor
MitraStar GPT-2541GNAC Firewall Settings Page settings-firewall.cgi os command injection
MediumCVSS 5.1No exploitEPSS 23%mitrastar · gpt-2541gnacOct 15, 2024