Thecus records
5 published records for vendor thecus.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 3
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-255 Credentials Management Errors2
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')2
- CWE-94 Improper Control of Generation of Code ('Code Injection')1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
5 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
41Plan | CVE-2013-5667No exploit | The Thecus NAS server N8800 with firmware 5.03.01 allows remote attackers to execute arbitrary commands via a get_userid action with shell mthecus · n8800 nas server firmware · CWE-78 | Critical10.0 | — | 4.2% | Jan 24, 2014 |
40Plan | CVE-2021-34111No exploit | Thecus 4800Eco was discovered to contain a command injection vulnerability via the username parameter in /adm/setmain.php.thecus · n4800eco firmware · CWE-78 | Critical9.8 | — | 2.7% | May 19, 2022 |
32Monitor | CVE-2013-5669No exploit | The Thecus NAS server N8800 with firmware 5.03.01 uses cleartext credentials for administrative authentication, which allows remote attackerthecus · n8800 nas server firmware · CWE-255 | High7.8 | — | 2.2% | Jan 24, 2014 |
32Monitor | CVE-2013-5668No exploit | The ADS/NT Support page on the Thecus NAS server N8800 with firmware 5.03.01 allows remote attackers to discover the administrator credentiathecus · n8800 nas server firmware · CWE-255 | High7.8 | — | 2.1% | Jan 24, 2014 |
28Monitor | CVE-2008-0804Proof of concept | PHP remote file inclusion vulnerability in usrgetform.html in Thecus N5200Pro NAS Server allows remote attackers to execute arbitrary PHP cothecus · n5200pro nas server control panel · CWE-94 | Medium6.8 | — | 2.0% | Feb 18, 2008 |
- CVE-2013-566741Plan
The Thecus NAS server N8800 with firmware 5.03.01 allows remote attackers to execute arbitrary commands via a get_userid action with shell m
CriticalCVSS 10.0No exploitEPSS 4%thecus · n8800 nas server firmwareJan 24, 2014
- CVE-2021-3411140Plan
Thecus 4800Eco was discovered to contain a command injection vulnerability via the username parameter in /adm/setmain.php.
CriticalCVSS 9.8No exploitEPSS 3%thecus · n4800eco firmwareMay 19, 2022
- CVE-2013-566932Monitor
The Thecus NAS server N8800 with firmware 5.03.01 uses cleartext credentials for administrative authentication, which allows remote attacker
HighCVSS 7.8No exploitEPSS 2%thecus · n8800 nas server firmwareJan 24, 2014
- CVE-2013-566832Monitor
The ADS/NT Support page on the Thecus NAS server N8800 with firmware 5.03.01 allows remote attackers to discover the administrator credentia
HighCVSS 7.8No exploitEPSS 2%thecus · n8800 nas server firmwareJan 24, 2014
- CVE-2008-080428Monitor
PHP remote file inclusion vulnerability in usrgetform.html in Thecus N5200Pro NAS Server allows remote attackers to execute arbitrary PHP co
MediumCVSS 6.8Proof of conceptEPSS 2%thecus · n5200pro nas server control panelFeb 18, 2008