Arris kayıtları
arris üreticisine ait 28 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 3 · %10,7
- Pre-auth RCE
- 7
- Düzeltme kaydı olan
- %0
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')6
- CWE-352 Cross-Site Request Forgery (CSRF)3
- CWE-77 Improper Neutralization of Special Elements used in a Command ('Command Injection')3
- CWE-255 Credentials Management Errors3
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')3
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor2
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
28 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
59Planlayın | CVE-2014-8423Silahlaştırılmış | Unspecified vulnerability in the management portal in ARRIS VAP2500 before FW08.41 allows remote attackers to execute arbitrary commands viaarris · vap2500 firmware · CWE-74 | Kritik10,0 | — | %62,5 | 28 Kas 2014 |
49Planlayın | CVE-2014-8424Silahlaştırılmış | ARRIS VAP2500 before FW08.41 does not properly validate passwords, which allows remote attackers to bypass authentication.arris · vap2500 firmware · CWE-287 | Yüksek7,8 | — | %59,6 | 28 Kas 2014 |
41Planlayın | CVE-2014-9406İstismar yok | ARRIS Touchstone TG862G/CT Telephony Gateway with firmware 7.6.59S.CT and earlier has a default password of password for the admin account, arris · touchstone tg862g\/ct firmware · CWE-255 | Kritik10,0 | — | %2,1 | 18 Ara 2014 |
40Planlayın | CVE-2022-26994İstismar yok | Arris routers SBR-AC1900P 1.0.7-B05, SBR-AC3200P 1.0.7-B05 and SBR-AC1200P 1.0.5-B05 were discovered to contain a command injection vulnerabarris · sbr-ac1900p firmware · CWE-78 | Kritik9,8 | — | %3,0 | 15 Mar 2022 |
40Planlayın | CVE-2022-26992İstismar yok | Arris routers SBR-AC1900P 1.0.7-B05, SBR-AC3200P 1.0.7-B05 and SBR-AC1200P 1.0.5-B05 were discovered to contain a command injection vulnerabarris · sbr-ac1900p firmware · CWE-78 | Kritik9,8 | — | %2,9 | 15 Mar 2022 |
40Planlayın | CVE-2022-26990İstismar yok | Arris routers SBR-AC1900P 1.0.7-B05, SBR-AC3200P 1.0.7-B05 and SBR-AC1200P 1.0.5-B05 were discovered to contain a command injection vulnerabarris · sbr-ac1900p firmware · CWE-78 | Kritik9,8 | — | %2,9 | 15 Mar 2022 |
40Planlayın | CVE-2022-26991İstismar yok | Arris routers SBR-AC1900P 1.0.7-B05, SBR-AC3200P 1.0.7-B05 and SBR-AC1200P 1.0.5-B05 were discovered to contain a command injection vulnerabarris · sbr-ac1900p firmware · CWE-78 | Kritik9,8 | — | %2,7 | 15 Mar 2022 |
40Planlayın | CVE-2022-26993İstismar yok | Arris routers SBR-AC1900P 1.0.7-B05, SBR-AC3200P 1.0.7-B05 and SBR-AC1200P 1.0.5-B05 were discovered to contain a command injection vulnerabarris · sbr-ac1900p firmware · CWE-78 | Kritik9,8 | — | %2,7 | 15 Mar 2022 |
40Planlayın | CVE-2018-20383İstismar yok | ARRIS DG950A 7.10.145 and DG950S 7.10.145.EURO devices allow remote attackers to discover credentials via iso.3.6.1.4.1.4491.2.4.1.1.6.1.1.0arris · dg950s firmware · CWE-522 | Kritik9,8 | — | %1,8 | 23 Ara 2018 |
39İzleyin | CVE-2023-40039İstismar yok | An issue was discovered on ARRIS TG852G, TG862G, and TG1672G devices.arris · tg852g firmware · CWE-284 | Kritik9,8 | — | %1,2 | 11 Eyl 2023 |
38İzleyin | CVE-2015-7289İstismar yok | Arris DG860A, TG862A, and TG862G devices with firmware TS0703128_100611 through TS0705125D_031115 have a hardcoded administrator password dearris · na model 862 gw mono firmware · CWE-255 | Kritik9,3 | — | %2,1 | 21 Kas 2015 |
35İzleyin | CVE-2022-31793Kavram kanıtı | do_request in request.c in muhttpd before 1.1.7 allows remote attackers to read arbitrary files by constructing a URL with a single characteinglorion · muhttpd · CWE-22 | Yüksek7,5 | — | %16,9 | 4 Ağu 2022 |
35İzleyin | CVE-2017-9490İstismar yok | The Comcast firmware on Arris TG1682G (eMTA&DOCSIS version 10.0.132.SIP.PC20.CT, software version TG1682_2.2p7s2_PROD_sey) devices allows coarris · tg1682g firmware · CWE-352 | Yüksek8,8 | — | %0,5 | 30 Tem 2017 |
35İzleyin | CVE-2024-25729İstismar yok | Arris SBG6580 devices have predictable default WPA2 security passwords that could lead to unauthorized remote access.CWE-521 | Yüksek8,8 | — | %0,5 | 7 Mar 2024 |
35İzleyin | CVE-2023-40038İstismar yok | Arris DG860A and DG1670A devices have predictable default WPA2 PSKs that could lead to unauthorized remote access.arris · dg860a firmware · CWE-287 | Yüksek8,8 | — | %0,4 | 27 Ara 2023 |
32İzleyin | CVE-2014-8425Kavram kanıtı | The management portal in ARRIS VAP2500 before FW08.41 allows remote attackers to obtain credentials by reading the configuration files.arris · vap2500 firmware · CWE-200 | Yüksek7,8 | — | %3,1 | 28 Kas 2014 |
32İzleyin | CVE-2007-2796İstismar yok | Arris Cadant C3 CMTS allows remote attackers to cause a denial of service (service termination) via a malformed IP packet with an invalid IParris · cadant c3 cmts | Yüksek7,8 | — | %2,2 | 12 Haz 2007 |
28İzleyin | CVE-2020-8438İstismar yok | Ruckus ZoneFlex R500 104.0.0.0.1347 devices allow an authenticated attacker to execute arbitrary OS commands via the hidden /forms/nslookupHarris · ruckus zoneflex r500 firmware · CWE-78 | Yüksek7,2 | — | %1,6 | 29 Oca 2020 |
27İzleyin | CVE-2024-5195İstismar yok | Arris VAP2500 diag_s.php command injectionarris · vap2500 firmware · CWE-77 | Orta5,1 | — | %23,4 | 22 May 2024 |
27İzleyin | CVE-2024-5196İstismar yok | Arris VAP2500 tools_command.php command injectionarris · vap2500 firmware · CWE-77 | Orta5,1 | — | %23,4 | 22 May 2024 |
27İzleyin | CVE-2015-7291İstismar yok | Cross-site request forgery (CSRF) vulnerability in adv_pwd_cgi in the web management interface on Arris DG860A, TG862A, and TG862G devices warris · na model 862 gw mono firmware · CWE-352 | Orta6,8 | — | %1,0 | 21 Kas 2015 |
27İzleyin | CVE-2014-5437İstismar yok | Multiple cross-site request forgery (CSRF) vulnerabilities in ARRIS Touchstone TG862G/CT Telephony Gateway with firmware 7.6.59S.CT and earlarris · touchstone tg862g\/ct firmware · CWE-352 | Orta6,8 | — | %0,6 | 17 Ara 2014 |
25İzleyin | CVE-2014-4863Silahlaştırılmış | The Arris Touchstone DG950A cable modem with software 7.10.131 has an SNMP community of public, which allows remote attackers to obtain sensarris · touchstone dg950a software · CWE-200 | Orta5,0 | — | %15,7 | 5 Eyl 2014 |
24İzleyin | CVE-2022-45028İstismar yok | A cross-site scripting (XSS) vulnerability in Arris NVG443B 9.3.0h3d36 allows attackers to execute arbitrary web scripts or HTML via a craftarris · nvg443b firmware · CWE-79 | Orta6,1 | — | %0,5 | 13 Ara 2022 |
21İzleyin | CVE-2024-5194İstismar yok | Arris VAP2500 assoc_table.php command injectionarris · vap2500 firmware · CWE-77 | Orta5,1 | — | %3,6 | 22 May 2024 |
- CVE-2014-842359Planlayın
Unspecified vulnerability in the management portal in ARRIS VAP2500 before FW08.41 allows remote attackers to execute arbitrary commands via
KritikCVSS 10,0SilahlaştırılmışEPSS %62arris · vap2500 firmware28 Kas 2014
- CVE-2014-842449Planlayın
ARRIS VAP2500 before FW08.41 does not properly validate passwords, which allows remote attackers to bypass authentication.
YüksekCVSS 7,8SilahlaştırılmışEPSS %60arris · vap2500 firmware28 Kas 2014
- CVE-2014-940641Planlayın
ARRIS Touchstone TG862G/CT Telephony Gateway with firmware 7.6.59S.CT and earlier has a default password of password for the admin account,
KritikCVSS 10,0İstismar yokEPSS %2arris · touchstone tg862g\/ct firmware18 Ara 2014
- CVE-2022-2699440Planlayın
Arris routers SBR-AC1900P 1.0.7-B05, SBR-AC3200P 1.0.7-B05 and SBR-AC1200P 1.0.5-B05 were discovered to contain a command injection vulnerab
KritikCVSS 9,8İstismar yokEPSS %3arris · sbr-ac1900p firmware15 Mar 2022
- CVE-2022-2699240Planlayın
Arris routers SBR-AC1900P 1.0.7-B05, SBR-AC3200P 1.0.7-B05 and SBR-AC1200P 1.0.5-B05 were discovered to contain a command injection vulnerab
KritikCVSS 9,8İstismar yokEPSS %3arris · sbr-ac1900p firmware15 Mar 2022
- CVE-2022-2699040Planlayın
Arris routers SBR-AC1900P 1.0.7-B05, SBR-AC3200P 1.0.7-B05 and SBR-AC1200P 1.0.5-B05 were discovered to contain a command injection vulnerab
KritikCVSS 9,8İstismar yokEPSS %3arris · sbr-ac1900p firmware15 Mar 2022
- CVE-2022-2699140Planlayın
Arris routers SBR-AC1900P 1.0.7-B05, SBR-AC3200P 1.0.7-B05 and SBR-AC1200P 1.0.5-B05 were discovered to contain a command injection vulnerab
KritikCVSS 9,8İstismar yokEPSS %3arris · sbr-ac1900p firmware15 Mar 2022
- CVE-2022-2699340Planlayın
Arris routers SBR-AC1900P 1.0.7-B05, SBR-AC3200P 1.0.7-B05 and SBR-AC1200P 1.0.5-B05 were discovered to contain a command injection vulnerab
KritikCVSS 9,8İstismar yokEPSS %3arris · sbr-ac1900p firmware15 Mar 2022
- CVE-2018-2038340Planlayın
ARRIS DG950A 7.10.145 and DG950S 7.10.145.EURO devices allow remote attackers to discover credentials via iso.3.6.1.4.1.4491.2.4.1.1.6.1.1.0
KritikCVSS 9,8İstismar yokEPSS %2arris · dg950s firmware23 Ara 2018
- CVE-2023-4003939İzleyin
An issue was discovered on ARRIS TG852G, TG862G, and TG1672G devices.
KritikCVSS 9,8İstismar yokEPSS %1arris · tg852g firmware11 Eyl 2023
- CVE-2015-728938İzleyin
Arris DG860A, TG862A, and TG862G devices with firmware TS0703128_100611 through TS0705125D_031115 have a hardcoded administrator password de
KritikCVSS 9,3İstismar yokEPSS %2arris · na model 862 gw mono firmware21 Kas 2015
- CVE-2022-3179335İzleyin
do_request in request.c in muhttpd before 1.1.7 allows remote attackers to read arbitrary files by constructing a URL with a single characte
YüksekCVSS 7,5Kavram kanıtıEPSS %17inglorion · muhttpd4 Ağu 2022
- CVE-2017-949035İzleyin
The Comcast firmware on Arris TG1682G (eMTA&DOCSIS version 10.0.132.SIP.PC20.CT, software version TG1682_2.2p7s2_PROD_sey) devices allows co
YüksekCVSS 8,8İstismar yokEPSS %1arris · tg1682g firmware30 Tem 2017
- CVE-2024-2572935İzleyin
Arris SBG6580 devices have predictable default WPA2 security passwords that could lead to unauthorized remote access.
YüksekCVSS 8,8İstismar yokEPSS %07 Mar 2024
- CVE-2023-4003835İzleyin
Arris DG860A and DG1670A devices have predictable default WPA2 PSKs that could lead to unauthorized remote access.
YüksekCVSS 8,8İstismar yokEPSS %0arris · dg860a firmware27 Ara 2023
- CVE-2014-842532İzleyin
The management portal in ARRIS VAP2500 before FW08.41 allows remote attackers to obtain credentials by reading the configuration files.
YüksekCVSS 7,8Kavram kanıtıEPSS %3arris · vap2500 firmware28 Kas 2014
- CVE-2007-279632İzleyin
Arris Cadant C3 CMTS allows remote attackers to cause a denial of service (service termination) via a malformed IP packet with an invalid IP
YüksekCVSS 7,8İstismar yokEPSS %2arris · cadant c3 cmts12 Haz 2007
- CVE-2020-843828İzleyin
Ruckus ZoneFlex R500 104.0.0.0.1347 devices allow an authenticated attacker to execute arbitrary OS commands via the hidden /forms/nslookupH
YüksekCVSS 7,2İstismar yokEPSS %2arris · ruckus zoneflex r500 firmware29 Oca 2020
- CVE-2024-519527İzleyin
Arris VAP2500 diag_s.php command injection
OrtaCVSS 5,1İstismar yokEPSS %23arris · vap2500 firmware22 May 2024
- CVE-2024-519627İzleyin
Arris VAP2500 tools_command.php command injection
OrtaCVSS 5,1İstismar yokEPSS %23arris · vap2500 firmware22 May 2024
- CVE-2015-729127İzleyin
Cross-site request forgery (CSRF) vulnerability in adv_pwd_cgi in the web management interface on Arris DG860A, TG862A, and TG862G devices w
OrtaCVSS 6,8İstismar yokEPSS %1arris · na model 862 gw mono firmware21 Kas 2015
- CVE-2014-543727İzleyin
Multiple cross-site request forgery (CSRF) vulnerabilities in ARRIS Touchstone TG862G/CT Telephony Gateway with firmware 7.6.59S.CT and earl
OrtaCVSS 6,8İstismar yokEPSS %1arris · touchstone tg862g\/ct firmware17 Ara 2014
- CVE-2014-486325İzleyin
The Arris Touchstone DG950A cable modem with software 7.10.131 has an SNMP community of public, which allows remote attackers to obtain sens
OrtaCVSS 5,0SilahlaştırılmışEPSS %16arris · touchstone dg950a software5 Eyl 2014
- CVE-2022-4502824İzleyin
A cross-site scripting (XSS) vulnerability in Arris NVG443B 9.3.0h3d36 allows attackers to execute arbitrary web scripts or HTML via a craft
OrtaCVSS 6,1İstismar yokEPSS %1arris · nvg443b firmware13 Ara 2022
- CVE-2024-519421İzleyin
Arris VAP2500 assoc_table.php command injection
OrtaCVSS 5,1İstismar yokEPSS %4arris · vap2500 firmware22 May 2024