Записи IP-COM
21 опубликованных записей вендора ip-com.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 5
- С записью об исправлении
- 0 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-120 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')13
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')4
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer1
- CWE-77 Improper Neutralization of Special Elements used in a Command ('Command Injection')1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
21 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
45В плане | CVE-2022-45711Эксплойта нет | IP-COM M50 V15.11.0.33(10768) was discovered to contain a command injection vulnerability via the hostname parameter in the formSetNetCheckTip-com · m50 firmware · CWE-78 | Критическая9,8 | — | 20,2 % | 23 дек. 2022 г. |
41В плане | CVE-2022-45005Эксплойта нет | IP-COM EW9 V15.11.0.14(9732) was discovered to contain a command injection vulnerability in the cmd_get_ping_output function.ip-com · ew9 firmware · CWE-78 | Критическая9,8 | — | 5,4 % | 13 дек. 2022 г. |
41В плане | CVE-2022-43367Эксплойта нет | IP-COM EW9 V15.11.0.14(9732) was discovered to contain a command injection vulnerability in the formSetDebugCfg function.ip-com · ew9 firmware · CWE-77 | Критическая9,8 | — | 5,2 % | 27 окт. 2022 г. |
40В плане | CVE-2022-45709Эксплойта нет | IP-COM M50 V15.11.0.33(10768) was discovered to contain multiple command injection vulnerabilities via the pEnable, pLevel, and pModule paraip-com · m50 firmware · CWE-78 | Критическая9,8 | — | 4,3 % | 23 дек. 2022 г. |
40В плане | CVE-2022-45717Эксплойта нет | IP-COM M50 V15.11.0.33(10768) was discovered to contain a command injection vulnerability via the usbPartitionName parameter in the formSetUip-com · m50 firmware · CWE-78 | Критическая9,8 | — | 4,3 % | 23 дек. 2022 г. |
39Наблюдать | CVE-2022-45708Эксплойта нет | IP-COM M50 V15.11.0.33(10768) was discovered to contain a buffer overflow via the sPortMapIndex parameter in the formDelPortMapping functionip-com · m50 firmware · CWE-120 | Критическая9,8 | — | 1,1 % | 23 дек. 2022 г. |
39Наблюдать | CVE-2022-45710Эксплойта нет | IP-COM M50 V15.11.0.33(10768) was discovered to contain multiple buffer overflows via the pEnable, pLevel, and pModule parameters in the forip-com · m50 firmware · CWE-120 | Критическая9,8 | — | 1,1 % | 23 дек. 2022 г. |
39Наблюдать | CVE-2022-45712Эксплойта нет | IP-COM M50 V15.11.0.33(10768) was discovered to contain a buffer overflow via the rules parameter in the formAddDnsForward function.ip-com · m50 firmware · CWE-120 | Критическая9,8 | — | 1,1 % | 23 дек. 2022 г. |
39Наблюдать | CVE-2022-45714Эксплойта нет | IP-COM M50 V15.11.0.33(10768) was discovered to contain a buffer overflow via the indexSet parameter in the formQOSRuleDel function.ip-com · m50 firmware · CWE-120 | Критическая9,8 | — | 1,1 % | 23 дек. 2022 г. |
39Наблюдать | CVE-2022-45715Эксплойта нет | IP-COM M50 V15.11.0.33(10768) was discovered to contain multiple buffer overflows via the pLanPortRange and pWanPortRange parameters in the ip-com · m50 firmware · CWE-120 | Критическая9,8 | — | 1,1 % | 23 дек. 2022 г. |
39Наблюдать | CVE-2022-45716Эксплойта нет | IP-COM M50 V15.11.0.33(10768) was discovered to contain a buffer overflow via the indexSet parameter in the formIPMacBindDel function.ip-com · m50 firmware · CWE-120 | Критическая9,8 | — | 1,1 % | 23 дек. 2022 г. |
39Наблюдать | CVE-2022-45719Эксплойта нет | IP-COM M50 V15.11.0.33(10768) was discovered to contain a buffer overflow via the gotoUrl parameter in the formPortalAuth function.ip-com · m50 firmware · CWE-120 | Критическая9,8 | — | 1,1 % | 23 дек. 2022 г. |
39Наблюдать | CVE-2022-45718Эксплойта нет | IP-COM M50 V15.11.0.33(10768) was discovered to contain a buffer overflow via the rules parameter in the formIPMacBindAdd function.ip-com · m50 firmware · CWE-120 | Критическая9,8 | — | 1,1 % | 23 дек. 2022 г. |
39Наблюдать | CVE-2022-45721Эксплойта нет | IP-COM M50 V15.11.0.33(10768) was discovered to contain a buffer overflow via the picName parameter in the formDelWewifiPic function.ip-com · m50 firmware · CWE-120 | Критическая9,8 | — | 1,1 % | 23 дек. 2022 г. |
39Наблюдать | CVE-2022-45720Эксплойта нет | IP-COM M50 V15.11.0.33(10768) was discovered to contain multiple buffer overflows via the ip, mac, and remark parameters in the formIPMacBinip-com · m50 firmware · CWE-120 | Критическая9,8 | — | 1,1 % | 23 дек. 2022 г. |
39Наблюдать | CVE-2022-45706Эксплойта нет | IP-COM M50 V15.11.0.33(10768) was discovered to contain a buffer overflow via the hostname parameter in the formSetNetCheckTools function.ip-com · m50 firmware · CWE-120 | Критическая9,8 | — | 1,1 % | 23 дек. 2022 г. |
39Наблюдать | CVE-2022-45707Эксплойта нет | IP-COM M50 V15.11.0.33(10768) was discovered to contain a buffer overflow via the rules parameter in the formAddDnsHijack function.ip-com · m50 firmware · CWE-120 | Критическая9,8 | — | 1,1 % | 23 дек. 2022 г. |
36Наблюдать | CVE-2026-2017Эксплойта нет | IP-COM W30AP POST Request wx3auth R7WebsSecurityHandler stack-based overflowip-com · w30ap firmware · CWE-119 | Высокая8,9 | — | 4,6 % | 6 февр. 2026 г. |
30Наблюдать | CVE-2022-43365Эксплойта нет | IP-COM EW9 V15.11.0.14(9732) was discovered to contain a buffer overflow in the formSetDebugCfg function.ip-com · ew9 firmware · CWE-120 | Высокая7,5 | — | 0,9 % | 27 окт. 2022 г. |
30Наблюдать | CVE-2022-43366Эксплойта нет | IP-COM EW9 V15.11.0.14(9732) allows unauthenticated attackers to access sensitive information via the checkLoginUser, ate, telnet, version, ip-com · ew9 firmware | Высокая7,5 | — | 0,8 % | 27 окт. 2022 г. |
30Наблюдать | CVE-2022-43364Эксплойта нет | An access control issue in the password reset page of IP-COM EW9 V15.11.0.14(9732) allows unauthenticated attackers to arbitrarily change thip-com · ew9 firmware | Высокая7,5 | — | 0,7 % | 27 окт. 2022 г. |
- CVE-2022-4571145В плане
IP-COM M50 V15.11.0.33(10768) was discovered to contain a command injection vulnerability via the hostname parameter in the formSetNetCheckT
КритическаяCVSS 9,8Эксплойта нетEPSS 20 %ip-com · m50 firmware23 дек. 2022 г.
- CVE-2022-4500541В плане
IP-COM EW9 V15.11.0.14(9732) was discovered to contain a command injection vulnerability in the cmd_get_ping_output function.
КритическаяCVSS 9,8Эксплойта нетEPSS 5 %ip-com · ew9 firmware13 дек. 2022 г.
- CVE-2022-4336741В плане
IP-COM EW9 V15.11.0.14(9732) was discovered to contain a command injection vulnerability in the formSetDebugCfg function.
КритическаяCVSS 9,8Эксплойта нетEPSS 5 %ip-com · ew9 firmware27 окт. 2022 г.
- CVE-2022-4570940В плане
IP-COM M50 V15.11.0.33(10768) was discovered to contain multiple command injection vulnerabilities via the pEnable, pLevel, and pModule para
КритическаяCVSS 9,8Эксплойта нетEPSS 4 %ip-com · m50 firmware23 дек. 2022 г.
- CVE-2022-4571740В плане
IP-COM M50 V15.11.0.33(10768) was discovered to contain a command injection vulnerability via the usbPartitionName parameter in the formSetU
КритическаяCVSS 9,8Эксплойта нетEPSS 4 %ip-com · m50 firmware23 дек. 2022 г.
- CVE-2022-4570839Наблюдать
IP-COM M50 V15.11.0.33(10768) was discovered to contain a buffer overflow via the sPortMapIndex parameter in the formDelPortMapping function
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %ip-com · m50 firmware23 дек. 2022 г.
- CVE-2022-4571039Наблюдать
IP-COM M50 V15.11.0.33(10768) was discovered to contain multiple buffer overflows via the pEnable, pLevel, and pModule parameters in the for
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %ip-com · m50 firmware23 дек. 2022 г.
- CVE-2022-4571239Наблюдать
IP-COM M50 V15.11.0.33(10768) was discovered to contain a buffer overflow via the rules parameter in the formAddDnsForward function.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %ip-com · m50 firmware23 дек. 2022 г.
- CVE-2022-4571439Наблюдать
IP-COM M50 V15.11.0.33(10768) was discovered to contain a buffer overflow via the indexSet parameter in the formQOSRuleDel function.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %ip-com · m50 firmware23 дек. 2022 г.
- CVE-2022-4571539Наблюдать
IP-COM M50 V15.11.0.33(10768) was discovered to contain multiple buffer overflows via the pLanPortRange and pWanPortRange parameters in the
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %ip-com · m50 firmware23 дек. 2022 г.
- CVE-2022-4571639Наблюдать
IP-COM M50 V15.11.0.33(10768) was discovered to contain a buffer overflow via the indexSet parameter in the formIPMacBindDel function.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %ip-com · m50 firmware23 дек. 2022 г.
- CVE-2022-4571939Наблюдать
IP-COM M50 V15.11.0.33(10768) was discovered to contain a buffer overflow via the gotoUrl parameter in the formPortalAuth function.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %ip-com · m50 firmware23 дек. 2022 г.
- CVE-2022-4571839Наблюдать
IP-COM M50 V15.11.0.33(10768) was discovered to contain a buffer overflow via the rules parameter in the formIPMacBindAdd function.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %ip-com · m50 firmware23 дек. 2022 г.
- CVE-2022-4572139Наблюдать
IP-COM M50 V15.11.0.33(10768) was discovered to contain a buffer overflow via the picName parameter in the formDelWewifiPic function.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %ip-com · m50 firmware23 дек. 2022 г.
- CVE-2022-4572039Наблюдать
IP-COM M50 V15.11.0.33(10768) was discovered to contain multiple buffer overflows via the ip, mac, and remark parameters in the formIPMacBin
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %ip-com · m50 firmware23 дек. 2022 г.
- CVE-2022-4570639Наблюдать
IP-COM M50 V15.11.0.33(10768) was discovered to contain a buffer overflow via the hostname parameter in the formSetNetCheckTools function.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %ip-com · m50 firmware23 дек. 2022 г.
- CVE-2022-4570739Наблюдать
IP-COM M50 V15.11.0.33(10768) was discovered to contain a buffer overflow via the rules parameter in the formAddDnsHijack function.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %ip-com · m50 firmware23 дек. 2022 г.
- CVE-2026-201736Наблюдать
IP-COM W30AP POST Request wx3auth R7WebsSecurityHandler stack-based overflow
ВысокаяCVSS 8,9Эксплойта нетEPSS 5 %ip-com · w30ap firmware6 февр. 2026 г.
- CVE-2022-4336530Наблюдать
IP-COM EW9 V15.11.0.14(9732) was discovered to contain a buffer overflow in the formSetDebugCfg function.
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %ip-com · ew9 firmware27 окт. 2022 г.
- CVE-2022-4336630Наблюдать
IP-COM EW9 V15.11.0.14(9732) allows unauthenticated attackers to access sensitive information via the checkLoginUser, ate, telnet, version,
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %ip-com · ew9 firmware27 окт. 2022 г.
- CVE-2022-4336430Наблюдать
An access control issue in the password reset page of IP-COM EW9 V15.11.0.14(9732) allows unauthenticated attackers to arbitrarily change th
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %ip-com · ew9 firmware27 окт. 2022 г.