Записи Digisol
10 опубликованных записей вендора digisol.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 0
- С записью об исправлении
- 0 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')4
- CWE-1191 On-Chip Debug and Test Interface With Improper Access Control1
- CWE-20 Improper Input Validation1
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer1
- CWE-352 Cross-Site Request Forgery (CSRF)1
- CWE-565 Reliance on Cookies without Validation and Integrity Checking1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEПрофиль атаки
Все записи
10 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
42В плане | CVE-2018-12706Proof of concept | DIGISOL DG-BR4000NG devices have a Buffer Overflow via a long Authorization HTTP header.digisol · dg-br4000ng firmware · CWE-119 | Критическая9,8 | — | 9,9 % | 24 июн. 2018 г. |
36Наблюдать | CVE-2017-6896Proof of concept | Privilege escalation vulnerability on the DIGISOL DG-HR1400 1.00.02 wireless router enables an attacker to escalate from user privilege to adigisol · dg-hr1400 router firmware · CWE-565 | Высокая8,8 | — | 3,7 % | 14 мар. 2017 г. |
36Наблюдать | CVE-2024-2257Proof of concept | Password Policy Bypass Vulnerability in Digisol Routerdigisol · digisol router dg-gr1321 · CWE-20 | Критическая9,1 | — | 1,0 % | 14 мая 2024 г. |
35Наблюдать | CVE-2017-6127Эксплойта нет | Multiple cross-site request forgery (CSRF) vulnerabilities in the access portal on the DIGISOL DG-HR1400 Wireless Router with firmware 1.00.digisol · dg-hr1400 firmware · CWE-352 | Высокая8,8 | — | 0,8 % | 21 февр. 2017 г. |
27Наблюдать | CVE-2024-4231Proof of concept | Incorrect Access Control Vulnerability in Digisol Routerdigisol · digisol router dg-gr1321 · CWE-1191 | Средняя6,8 | — | 0,6 % | 14 мая 2024 г. |
25Наблюдать | CVE-2018-12705Proof of concept | DIGISOL DG-BR4000NG devices have XSS via the SSID (it is validated only on the client side).digisol · dg-br4000ng firmware · CWE-79 | Средняя6,1 | — | 2,3 % | 24 июн. 2018 г. |
24Наблюдать | CVE-2020-35262Proof of concept | Cross Site Scripting (XSS) vulnerability in Digisol DG-HR3400 can be exploited via the NTP server name in Time and date module and "Keyword"digisol · dg-hr3400 firmware · CWE-79 | Средняя6,1 | — | 0,9 % | 6 янв. 2021 г. |
24Наблюдать | CVE-2018-12715Эксплойта нет | DIGISOL DG-HR3400 devices have XSS via a modified SSID when the apssid value is unchanged.digisol · dg-hr3400 firmware · CWE-79 | Средняя6,1 | — | 0,9 % | 3 июл. 2019 г. |
24Наблюдать | CVE-2018-14027Эксплойта нет | Digisol Wireless Wifi Home Router HR-3300 allows XSS via the userid or password parameter to the admin login page.digisol · dg-hr-3300 firmware · CWE-79 | Средняя6,1 | — | 0,8 % | 5 июл. 2019 г. |
21Наблюдать | CVE-2024-4232Proof of concept | Password Storage in Plaintext Vulnerability in Digisol Routerdigisol · digisol router dg-gr1321 · CWE-256 | Средняя5,4 | — | 0,3 % | 14 мая 2024 г. |
- CVE-2018-1270642В плане
DIGISOL DG-BR4000NG devices have a Buffer Overflow via a long Authorization HTTP header.
КритическаяCVSS 9,8Proof of conceptEPSS 10 %digisol · dg-br4000ng firmware24 июн. 2018 г.
- CVE-2017-689636Наблюдать
Privilege escalation vulnerability on the DIGISOL DG-HR1400 1.00.02 wireless router enables an attacker to escalate from user privilege to a
ВысокаяCVSS 8,8Proof of conceptEPSS 4 %digisol · dg-hr1400 router firmware14 мар. 2017 г.
- CVE-2024-225736Наблюдать
Password Policy Bypass Vulnerability in Digisol Router
КритическаяCVSS 9,1Proof of conceptEPSS 1 %digisol · digisol router dg-gr132114 мая 2024 г.
- CVE-2017-612735Наблюдать
Multiple cross-site request forgery (CSRF) vulnerabilities in the access portal on the DIGISOL DG-HR1400 Wireless Router with firmware 1.00.
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %digisol · dg-hr1400 firmware21 февр. 2017 г.
- CVE-2024-423127Наблюдать
Incorrect Access Control Vulnerability in Digisol Router
СредняяCVSS 6,8Proof of conceptEPSS 1 %digisol · digisol router dg-gr132114 мая 2024 г.
- CVE-2018-1270525Наблюдать
DIGISOL DG-BR4000NG devices have XSS via the SSID (it is validated only on the client side).
СредняяCVSS 6,1Proof of conceptEPSS 2 %digisol · dg-br4000ng firmware24 июн. 2018 г.
- CVE-2020-3526224Наблюдать
Cross Site Scripting (XSS) vulnerability in Digisol DG-HR3400 can be exploited via the NTP server name in Time and date module and "Keyword"
СредняяCVSS 6,1Proof of conceptEPSS 1 %digisol · dg-hr3400 firmware6 янв. 2021 г.
- CVE-2018-1271524Наблюдать
DIGISOL DG-HR3400 devices have XSS via a modified SSID when the apssid value is unchanged.
СредняяCVSS 6,1Эксплойта нетEPSS 1 %digisol · dg-hr3400 firmware3 июл. 2019 г.
- CVE-2018-1402724Наблюдать
Digisol Wireless Wifi Home Router HR-3300 allows XSS via the userid or password parameter to the admin login page.
СредняяCVSS 6,1Эксплойта нетEPSS 1 %digisol · dg-hr-3300 firmware5 июл. 2019 г.
- CVE-2024-423221Наблюдать
Password Storage in Plaintext Vulnerability in Digisol Router
СредняяCVSS 5,4Proof of conceptEPSS 0 %digisol · digisol router dg-gr132114 мая 2024 г.