multitech records
6 published records for vendor multitech.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 2
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-255 Credentials Management Errors1
- CWE-352 Cross-Site Request Forgery (CSRF)1
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')1
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')1
The weakness classes this vendor ships most often: where to look.
CWEAll records
6 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
40Plan | CVE-2016-10512No exploit | MultiTech FaxFinder before 4.1.2 stores Passwords unencrypted for maintaining the test connectivity function of its LDAP configuration.multitech · faxfinder · CWE-255 | Critical9.8 | — | 2.1% | Sep 29, 2017 |
35Monitor | CVE-2023-25201No exploit | Cross Site Request Forgery (CSRF) vulnerability in MultiTech Conduit AP MTCAP2-L4E1 MTCAP2-L4E1-868-042A v.6.0.0 allows a remote attacker tomultitech · conduit ap mtcap2-l4e1-868-042a firmware · CWE-352 | High8.8 | — | 0.5% | Jul 7, 2023 |
30Monitor | CVE-2018-17562No exploit | Multi-Tech FaxFinder before 5.1.6 has SQL Injection via a status/call_details?oid= URI, allowing an attacker to extract the underlying databmultitech · faxfinder · CWE-89 | High7.5 | — | 1.5% | Oct 3, 2018 |
30Monitor | CVE-2003-0126No exploit | The web interface for SOHO Routefinder 550 firmware 4.63 and earlier, and possibly later versions, has a default "admin" account with a blanmultitech · routefinder 550 vpn | High7.5 | — | 1.3% | Mar 18, 2003 |
29Monitor | CVE-2020-7594No exploit | MultiTech Conduit MTCDT-LVW2-24XX 1.4.17-ocea-13592 devices allow remote authenticated administrators to execute arbitrary OS commands by namultitech · conduit mtcdt-lvw2-246a firmware · CWE-78 | High7.2 | — | 2.5% | Jan 21, 2020 |
23Monitor | CVE-2003-0125Proof of concept | Buffer overflow in the web interface for SOHO Routefinder 550 before firmware 4.63 allows remote attackers to cause a denial of service (rebmultitech · routefinder 550 vpn | Medium5.0 | — | 10.8% | Mar 18, 2003 |
- CVE-2016-1051240Plan
MultiTech FaxFinder before 4.1.2 stores Passwords unencrypted for maintaining the test connectivity function of its LDAP configuration.
CriticalCVSS 9.8No exploitEPSS 2%multitech · faxfinderSep 29, 2017
- CVE-2023-2520135Monitor
Cross Site Request Forgery (CSRF) vulnerability in MultiTech Conduit AP MTCAP2-L4E1 MTCAP2-L4E1-868-042A v.6.0.0 allows a remote attacker to
HighCVSS 8.8No exploitEPSS 1%multitech · conduit ap mtcap2-l4e1-868-042a firmwareJul 7, 2023
- CVE-2018-1756230Monitor
Multi-Tech FaxFinder before 5.1.6 has SQL Injection via a status/call_details?oid= URI, allowing an attacker to extract the underlying datab
HighCVSS 7.5No exploitEPSS 1%multitech · faxfinderOct 3, 2018
- CVE-2003-012630Monitor
The web interface for SOHO Routefinder 550 firmware 4.63 and earlier, and possibly later versions, has a default "admin" account with a blan
HighCVSS 7.5No exploitEPSS 1%multitech · routefinder 550 vpnMar 18, 2003
- CVE-2020-759429Monitor
MultiTech Conduit MTCDT-LVW2-24XX 1.4.17-ocea-13592 devices allow remote authenticated administrators to execute arbitrary OS commands by na
HighCVSS 7.2No exploitEPSS 2%multitech · conduit mtcdt-lvw2-246a firmwareJan 21, 2020
- CVE-2003-012523Monitor
Buffer overflow in the web interface for SOHO Routefinder 550 before firmware 4.63 allows remote attackers to cause a denial of service (reb
MediumCVSS 5.0Proof of conceptEPSS 11%multitech · routefinder 550 vpnMar 18, 2003