Записи NetModule
6 опубликованных записей вендора netmodule.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 0
- С записью об исправлении
- 50 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')1
- CWE-384 Session Fixation1
- CWE-522 Insufficiently Protected Credentials1
- CWE-532 Insertion of Sensitive Information into Log File1
- CWE-77 Improper Neutralization of Special Elements used in a Command ('Command Injection')1
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
6 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
44В плане | CVE-2023-0861Proof of concept | Authenticated Command Injection in NetModule NSRWnetmodule · netmodule router software · CWE-77 | Высокая8,8 | — | 28,7 % | 16 февр. 2023 г. |
39Наблюдать | CVE-2021-39290Эксплойта нет | Certain NetModule devices allow Limited Session Fixation via PHPSESSID.netmodule · netmodule router software · CWE-384 | Критическая9,8 | — | 1,5 % | 23 авг. 2021 г. |
36Наблюдать | CVE-2023-0862Эксплойта нет | Path Traversal in NetModule NSRWnetmodule · netmodule router software · CWE-22 | Высокая8,8 | — | 2,4 % | 16 февр. 2023 г. |
35Наблюдать | CVE-2021-39291Эксплойта нет | Certain NetModule devices allow credentials via GET parameters to CLI-PHP.netmodule · netmodule router software · CWE-532 | Высокая8,8 | — | 1,5 % | 23 авг. 2021 г. |
30Наблюдать | CVE-2021-39289Эксплойта нет | Certain NetModule devices have Insecure Password Handling (cleartext or reversible encryption), These models with firmware before 4.3.0.113,netmodule · netmodule router software · CWE-522 | Высокая7,5 | — | 1,1 % | 23 авг. 2021 г. |
26Наблюдать | CVE-2023-46306Эксплойта нет | The web administration interface in NetModule Router Software (NRSW) 4.6 before 4.6.0.106 and 4.8 before 4.8.0.101 executes an OS command conetmodule · netmodule router software · CWE-78 | Средняя6,6 | — | 1,0 % | 22 окт. 2023 г. |
- CVE-2023-086144В плане
Authenticated Command Injection in NetModule NSRW
ВысокаяCVSS 8,8Proof of conceptEPSS 29 %netmodule · netmodule router software16 февр. 2023 г.
- CVE-2021-3929039Наблюдать
Certain NetModule devices allow Limited Session Fixation via PHPSESSID.
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %netmodule · netmodule router software23 авг. 2021 г.
- CVE-2023-086236Наблюдать
Path Traversal in NetModule NSRW
ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %netmodule · netmodule router software16 февр. 2023 г.
- CVE-2021-3929135Наблюдать
Certain NetModule devices allow credentials via GET parameters to CLI-PHP.
ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %netmodule · netmodule router software23 авг. 2021 г.
- CVE-2021-3928930Наблюдать
Certain NetModule devices have Insecure Password Handling (cleartext or reversible encryption), These models with firmware before 4.3.0.113,
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %netmodule · netmodule router software23 авг. 2021 г.
- CVE-2023-4630626Наблюдать
The web administration interface in NetModule Router Software (NRSW) 4.6 before 4.6.0.106 and 4.8 before 4.8.0.101 executes an OS command co
СредняяCVSS 6,6Эксплойта нетEPSS 1 %netmodule · netmodule router software22 окт. 2023 г.