Записи evenroute
6 опубликованных записей вендора evenroute.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 1
- С записью об исправлении
- 0 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-287 Improper Authentication2
- CWE-521 Weak Password Requirements1
- CWE-532 Insertion of Sensitive Information into Log File1
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')1
- CWE-862 Missing Authorization1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
6 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
40В плане | CVE-2020-11967Эксплойта нет | In IQrouter through 3.3.1, remote attackers can control the device (restart network, reboot, upgrade, reset) because of Incorrect Access Conevenroute · iqrouter firmware · CWE-862 | Критическая9,8 | — | 3,3 % | 21 апр. 2020 г. |
40В плане | CVE-2020-11963Эксплойта нет | IQrouter through 3.3.1, when unconfigured, has multiple remote code execution vulnerabilities in the web-panel because of Bash Shell Metachaevenroute · iqrouter firmware · CWE-78 | Критическая9,8 | — | 3,2 % | 21 апр. 2020 г. |
40В плане | CVE-2020-11966Эксплойта нет | In IQrouter through 3.3.1, the Lua function reset_password in the web-panel allows remote attackers to change the root password arbitrarily.evenroute · iqrouter firmware · CWE-521 | Критическая9,8 | — | 3,1 % | 21 апр. 2020 г. |
40В плане | CVE-2020-11965Эксплойта нет | In IQrouter through 3.3.1, there is a root user without a password, which allows attackers to gain full remote access via SSH.evenroute · iqrouter firmware · CWE-287 | Критическая9,8 | — | 2,1 % | 21 апр. 2020 г. |
31Наблюдать | CVE-2020-11968Эксплойта нет | In the web-panel in IQrouter through 3.3.1, remote attackers can read system logs because of Incorrect Access Control.evenroute · iqrouter firmware · CWE-532 | Высокая7,5 | — | 2,7 % | 21 апр. 2020 г. |
31Наблюдать | CVE-2020-11964Эксплойта нет | In IQrouter through 3.3.1, the Lua function diag_set_password in the web-panel allows remote attackers to change the root password arbitrarievenroute · iqrouter firmware · CWE-287 | Высокая7,5 | — | 2,3 % | 21 апр. 2020 г. |
- CVE-2020-1196740В плане
In IQrouter through 3.3.1, remote attackers can control the device (restart network, reboot, upgrade, reset) because of Incorrect Access Con
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %evenroute · iqrouter firmware21 апр. 2020 г.
- CVE-2020-1196340В плане
IQrouter through 3.3.1, when unconfigured, has multiple remote code execution vulnerabilities in the web-panel because of Bash Shell Metacha
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %evenroute · iqrouter firmware21 апр. 2020 г.
- CVE-2020-1196640В плане
In IQrouter through 3.3.1, the Lua function reset_password in the web-panel allows remote attackers to change the root password arbitrarily.
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %evenroute · iqrouter firmware21 апр. 2020 г.
- CVE-2020-1196540В плане
In IQrouter through 3.3.1, there is a root user without a password, which allows attackers to gain full remote access via SSH.
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %evenroute · iqrouter firmware21 апр. 2020 г.
- CVE-2020-1196831Наблюдать
In the web-panel in IQrouter through 3.3.1, remote attackers can read system logs because of Incorrect Access Control.
ВысокаяCVSS 7,5Эксплойта нетEPSS 3 %evenroute · iqrouter firmware21 апр. 2020 г.
- CVE-2020-1196431Наблюдать
In IQrouter through 3.3.1, the Lua function diag_set_password in the web-panel allows remote attackers to change the root password arbitrari
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %evenroute · iqrouter firmware21 апр. 2020 г.