Записи Thecus
5 опубликованных записей вендора thecus.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 3
- С записью об исправлении
- 0 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-255 Credentials Management Errors2
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')2
- CWE-94 Improper Control of Generation of Code ('Code Injection')1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEПрофиль атаки
Все записи
5 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
41В плане | CVE-2013-5667Эксплойта нет | The Thecus NAS server N8800 with firmware 5.03.01 allows remote attackers to execute arbitrary commands via a get_userid action with shell mthecus · n8800 nas server firmware · CWE-78 | Критическая10,0 | — | 4,2 % | 24 янв. 2014 г. |
40В плане | CVE-2021-34111Эксплойта нет | Thecus 4800Eco was discovered to contain a command injection vulnerability via the username parameter in /adm/setmain.php.thecus · n4800eco firmware · CWE-78 | Критическая9,8 | — | 2,7 % | 19 мая 2022 г. |
32Наблюдать | CVE-2013-5669Эксплойта нет | The Thecus NAS server N8800 with firmware 5.03.01 uses cleartext credentials for administrative authentication, which allows remote attackerthecus · n8800 nas server firmware · CWE-255 | Высокая7,8 | — | 2,2 % | 24 янв. 2014 г. |
32Наблюдать | CVE-2013-5668Эксплойта нет | The ADS/NT Support page on the Thecus NAS server N8800 with firmware 5.03.01 allows remote attackers to discover the administrator credentiathecus · n8800 nas server firmware · CWE-255 | Высокая7,8 | — | 2,1 % | 24 янв. 2014 г. |
28Наблюдать | CVE-2008-0804Proof of concept | PHP remote file inclusion vulnerability in usrgetform.html in Thecus N5200Pro NAS Server allows remote attackers to execute arbitrary PHP cothecus · n5200pro nas server control panel · CWE-94 | Средняя6,8 | — | 2,0 % | 18 февр. 2008 г. |
- CVE-2013-566741В плане
The Thecus NAS server N8800 with firmware 5.03.01 allows remote attackers to execute arbitrary commands via a get_userid action with shell m
КритическаяCVSS 10,0Эксплойта нетEPSS 4 %thecus · n8800 nas server firmware24 янв. 2014 г.
- CVE-2021-3411140В плане
Thecus 4800Eco was discovered to contain a command injection vulnerability via the username parameter in /adm/setmain.php.
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %thecus · n4800eco firmware19 мая 2022 г.
- CVE-2013-566932Наблюдать
The Thecus NAS server N8800 with firmware 5.03.01 uses cleartext credentials for administrative authentication, which allows remote attacker
ВысокаяCVSS 7,8Эксплойта нетEPSS 2 %thecus · n8800 nas server firmware24 янв. 2014 г.
- CVE-2013-566832Наблюдать
The ADS/NT Support page on the Thecus NAS server N8800 with firmware 5.03.01 allows remote attackers to discover the administrator credentia
ВысокаяCVSS 7,8Эксплойта нетEPSS 2 %thecus · n8800 nas server firmware24 янв. 2014 г.
- CVE-2008-080428Наблюдать
PHP remote file inclusion vulnerability in usrgetform.html in Thecus N5200Pro NAS Server allows remote attackers to execute arbitrary PHP co
СредняяCVSS 6,8Proof of conceptEPSS 2 %thecus · n5200pro nas server control panel18 февр. 2008 г.