NetModule records
6 published records for vendor netmodule.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 50%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')1
- CWE-384 Session Fixation1
- CWE-522 Insufficiently Protected Credentials1
- CWE-532 Insertion of Sensitive Information into Log File1
- CWE-77 Improper Neutralization of Special Elements used in a Command ('Command Injection')1
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')1
The weakness classes this vendor ships most often: where to look.
CWEAll records
6 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
44Plan | CVE-2023-0861Proof of concept | Authenticated Command Injection in NetModule NSRWnetmodule · netmodule router software · CWE-77 | High8.8 | — | 28.7% | Feb 16, 2023 |
39Monitor | CVE-2021-39290No exploit | Certain NetModule devices allow Limited Session Fixation via PHPSESSID.netmodule · netmodule router software · CWE-384 | Critical9.8 | — | 1.5% | Aug 23, 2021 |
36Monitor | CVE-2023-0862No exploit | Path Traversal in NetModule NSRWnetmodule · netmodule router software · CWE-22 | High8.8 | — | 2.4% | Feb 16, 2023 |
35Monitor | CVE-2021-39291No exploit | Certain NetModule devices allow credentials via GET parameters to CLI-PHP.netmodule · netmodule router software · CWE-532 | High8.8 | — | 1.5% | Aug 23, 2021 |
30Monitor | CVE-2021-39289No exploit | Certain NetModule devices have Insecure Password Handling (cleartext or reversible encryption), These models with firmware before 4.3.0.113,netmodule · netmodule router software · CWE-522 | High7.5 | — | 1.1% | Aug 23, 2021 |
26Monitor | CVE-2023-46306No exploit | The web administration interface in NetModule Router Software (NRSW) 4.6 before 4.6.0.106 and 4.8 before 4.8.0.101 executes an OS command conetmodule · netmodule router software · CWE-78 | Medium6.6 | — | 1.0% | Oct 22, 2023 |
- CVE-2023-086144Plan
Authenticated Command Injection in NetModule NSRW
HighCVSS 8.8Proof of conceptEPSS 29%netmodule · netmodule router softwareFeb 16, 2023
- CVE-2021-3929039Monitor
Certain NetModule devices allow Limited Session Fixation via PHPSESSID.
CriticalCVSS 9.8No exploitEPSS 2%netmodule · netmodule router softwareAug 23, 2021
- CVE-2023-086236Monitor
Path Traversal in NetModule NSRW
HighCVSS 8.8No exploitEPSS 2%netmodule · netmodule router softwareFeb 16, 2023
- CVE-2021-3929135Monitor
Certain NetModule devices allow credentials via GET parameters to CLI-PHP.
HighCVSS 8.8No exploitEPSS 2%netmodule · netmodule router softwareAug 23, 2021
- CVE-2021-3928930Monitor
Certain NetModule devices have Insecure Password Handling (cleartext or reversible encryption), These models with firmware before 4.3.0.113,
HighCVSS 7.5No exploitEPSS 1%netmodule · netmodule router softwareAug 23, 2021
- CVE-2023-4630626Monitor
The web administration interface in NetModule Router Software (NRSW) 4.6 before 4.6.0.106 and 4.8 before 4.8.0.101 executes an OS command co
MediumCVSS 6.6No exploitEPSS 1%netmodule · netmodule router softwareOct 22, 2023