oringnet records
8 published records for vendor oringnet.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 1
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')3
- CWE-77 Improper Neutralization of Special Elements used in a Command ('Command Injection')2
- CWE-703 Improper Check or Handling of Exceptional Conditions1
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')1
- CWE-912 Hidden Functionality1
The weakness classes this vendor ships most often: where to look.
CWEAll records
8 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
42Plan | CVE-2024-55547No exploit | Remote Command Execution via SNMPoringnet · iap-420 firmware · CWE-77 | Critical9.3 | — | 17.4% | Dec 10, 2024 |
41Plan | CVE-2024-5411No exploit | Missing input validation and OS command integration of the input in the ORing IAP-420 web-interface allows authenticated command injection.Toringnet · iap-420 firmware · CWE-78 | High8.7 | — | 23.4% | May 28, 2024 |
39Monitor | CVE-2022-3203No exploit | ORing net IAP-420(+) Hidden Functionalityoringnet · iap-420\+ firmware · CWE-912 | Critical9.8 | — | 0.9% | Oct 21, 2022 |
38Monitor | CVE-2024-55544No exploit | Authenticated Command Injectionoringnet · iap-420 firmware · CWE-77 | High8.7 | — | 12.0% | Dec 10, 2024 |
37Monitor | CVE-2024-5410No exploit | Stored Cross-Site Scriptingoringnet · iap-420 firmware · CWE-79 | High8.3 | — | 13.7% | May 28, 2024 |
28Monitor | CVE-2024-55545No exploit | Reflected Cross-Site Scriptingoringnet · iap-420 firmware · CWE-79 | High7.1 | — | 0.3% | Dec 10, 2024 |
28Monitor | CVE-2024-55546No exploit | Stored Cross-Site Scriptingoringnet · iap-420 firmware · CWE-79 | High7.1 | — | 0.3% | Dec 10, 2024 |
27Monitor | CVE-2024-55548No exploit | Improper check of password character lenght in ORing IAP-420 allows a forced deadlock.oringnet · iap-420 firmware · CWE-703 | Medium6.9 | — | 0.5% | Dec 10, 2024 |
- CVE-2024-5554742Plan
Remote Command Execution via SNMP
CriticalCVSS 9.3No exploitEPSS 17%oringnet · iap-420 firmwareDec 10, 2024
- CVE-2024-541141Plan
Missing input validation and OS command integration of the input in the ORing IAP-420 web-interface allows authenticated command injection.T
HighCVSS 8.7No exploitEPSS 23%oringnet · iap-420 firmwareMay 28, 2024
- CVE-2022-320339Monitor
ORing net IAP-420(+) Hidden Functionality
CriticalCVSS 9.8No exploitEPSS 1%oringnet · iap-420\+ firmwareOct 21, 2022
- CVE-2024-5554438Monitor
Authenticated Command Injection
HighCVSS 8.7No exploitEPSS 12%oringnet · iap-420 firmwareDec 10, 2024
- CVE-2024-541037Monitor
Stored Cross-Site Scripting
HighCVSS 8.3No exploitEPSS 14%oringnet · iap-420 firmwareMay 28, 2024
- CVE-2024-5554528Monitor
Reflected Cross-Site Scripting
HighCVSS 7.1No exploitEPSS 0%oringnet · iap-420 firmwareDec 10, 2024
- CVE-2024-5554628Monitor
Stored Cross-Site Scripting
HighCVSS 7.1No exploitEPSS 0%oringnet · iap-420 firmwareDec 10, 2024
- CVE-2024-5554827Monitor
Improper check of password character lenght in ORing IAP-420 allows a forced deadlock.
MediumCVSS 6.9No exploitEPSS 0%oringnet · iap-420 firmwareDec 10, 2024