nepstech records
4 published records for vendor nepstech.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor1
- CWE-311 Missing Encryption of Sensitive Data1
- CWE-352 Cross-Site Request Forgery (CSRF)1
- CWE-94 Improper Control of Generation of Code ('Code Injection')1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
4 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
39Monitor | CVE-2024-42658Proof of concept | An issue in wishnet Nepstech Wifi Router NTPL-XPON1GFEVN v1.0 allows a remote attacker to obtain sensitive information via the cookie's paranepstech · ntpl-xpon1gfevn firmware · CWE-200 | Critical9.8 | — | 1.4% | Aug 19, 2024 |
35Monitor | CVE-2024-40119Proof of concept | Nepstech Wifi Router xpon (terminal) model NTPL-Xpon1GFEVN v.1.0 Firmware V2.0.1 contains a Cross-Site Request Forgery (CSRF) vulnerability CWE-352 | High8.8 | — | 0.5% | Jul 17, 2024 |
33Monitor | CVE-2024-37855No exploit | An issue in Nepstech Wifi Router xpon (terminal) NTPL-Xpon1GFEVN, hardware verstion 1.0 firmware 2.0.1 allows a remote attacker to execute aCWE-94 | High8.4 | — | 0.5% | Jun 25, 2024 |
30Monitor | CVE-2024-42657Proof of concept | An issue in wishnet Nepstech Wifi Router NTPL-XPON1GFEVN v1.0 allows a remote attacker to obtain sensitive information via the lack of encrynepstech · ntpl-xpon1gfevn firmware · CWE-311 | High7.5 | — | 0.5% | Aug 19, 2024 |
- CVE-2024-4265839Monitor
An issue in wishnet Nepstech Wifi Router NTPL-XPON1GFEVN v1.0 allows a remote attacker to obtain sensitive information via the cookie's para
CriticalCVSS 9.8Proof of conceptEPSS 1%nepstech · ntpl-xpon1gfevn firmwareAug 19, 2024
- CVE-2024-4011935Monitor
Nepstech Wifi Router xpon (terminal) model NTPL-Xpon1GFEVN v.1.0 Firmware V2.0.1 contains a Cross-Site Request Forgery (CSRF) vulnerability
HighCVSS 8.8Proof of conceptEPSS 0%Jul 17, 2024
- CVE-2024-3785533Monitor
An issue in Nepstech Wifi Router xpon (terminal) NTPL-Xpon1GFEVN, hardware verstion 1.0 firmware 2.0.1 allows a remote attacker to execute a
HighCVSS 8.4No exploitEPSS 0%Jun 25, 2024
- CVE-2024-4265730Monitor
An issue in wishnet Nepstech Wifi Router NTPL-XPON1GFEVN v1.0 allows a remote attacker to obtain sensitive information via the lack of encry
HighCVSS 7.5Proof of conceptEPSS 0%nepstech · ntpl-xpon1gfevn firmwareAug 19, 2024