aterm kayıtları
aterm üreticisine ait 11 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 1 · %9,1
- Silahlaştırılmış
- 1 · %9,1
- Pre-auth RCE
- 3
- Düzeltme kaydı olan
- %9,1
- Yayından KEV’e ortanca
- 3062 gün
Tekrar eden sınıflar
- CWE-352 Cross-Site Request Forgery (CSRF)3
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')3
- CWE-264 Permissions, Privileges, and Access Controls1
- CWE-306 Missing Authentication for Critical Function1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
11 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
99Hemen | CVE-2014-8361Silahlaştırılmış | The miniigd SOAP service in Realtek SDK allows remote attackers to execute arbitrary code via a crafted NewInternalClient request, as exploirealtek · realtek sdk | Kritik9,8 | KEV | %100,0 | 1 May 2015 |
35İzleyin | CVE-2021-20621İstismar yok | Cross-site request forgery (CSRF) vulnerability in Aterm WG2600HP firmware Ver1.0.2 and earlier, and Aterm WG2600HP2 firmware Ver1.0.2 and eaterm · wg2600hp firmware · CWE-352 | Yüksek8,8 | — | %0,6 | 28 Oca 2021 |
35İzleyin | CVE-2016-1168İstismar yok | Cross-site request forgery (CSRF) vulnerability on NEC Aterm WF800HP devices with firmware 1.0.17 and earlier allows remote attackers to hijaterm · wf800hp · CWE-352 | Yüksek8,8 | — | %0,6 | 1 Nis 2016 |
35İzleyin | CVE-2016-1167İstismar yok | Cross-site request forgery (CSRF) vulnerability on NEC Aterm WG300HP devices allows remote attackers to hijack the authentication of arbitraaterm · wg300hp · CWE-352 | Yüksek8,8 | — | %0,6 | 1 Nis 2016 |
31İzleyin | CVE-2017-12575İstismar yok | An issue was discovered on the NEC Aterm WG2600HP2 1.0.2.aterm · wg2600hp2 firmware · CWE-306 | Yüksek7,5 | — | %2,3 | 24 Ağu 2018 |
31İzleyin | CVE-2003-0024İstismar yok | The menuBar feature in aterm 0.42 allows attackers to modify menu options and execute arbitrary commands via a certain character escape sequaterm · aterm | Yüksek7,5 | — | %1,8 | 3 Mar 2003 |
31İzleyin | CVE-2003-0067İstismar yok | The aterm terminal emulator 0.42 allows attackers to modify the window title via a certain character escape sequence and then insert it backaterm · aterm | Yüksek7,5 | — | %1,8 | 18 Mar 2003 |
24İzleyin | CVE-2021-20620İstismar yok | Cross-site scripting vulnerability in Aterm WF800HP firmware Ver1.0.9 and earlier allows remote attackers to inject an arbitrary script via aterm · wg2600hp firmware · CWE-79 | Orta6,1 | — | %1,0 | 28 Oca 2021 |
24İzleyin | CVE-2021-20622İstismar yok | Cross-site scripting vulnerability in Aterm WG2600HP firmware Ver1.0.2 and earlier, and Aterm WG2600HP2 firmware Ver1.0.2 and earlier allowsaterm · wg2600hp firmware · CWE-79 | Orta6,1 | — | %1,0 | 28 Oca 2021 |
24İzleyin | CVE-2021-20710İstismar yok | Cross-site scripting vulnerability in Aterm WG2600HS firmware Ver1.5.1 and earlier allows remote attackers to inject an arbitrary script viaaterm · wg2600hs firmware · CWE-79 | Orta6,1 | — | %0,8 | 25 Nis 2021 |
14İzleyin | CVE-2008-1142İstismar yok | rxvt 2.6.4 opens a terminal window on :0 if the DISPLAY environment variable is not set, which might allow local users to hijack X11 connectrxvt · rxvt · CWE-264 | Düşük3,7 | — | %0,4 | 7 Nis 2008 |
- CVE-2014-836199Hemen
The miniigd SOAP service in Realtek SDK allows remote attackers to execute arbitrary code via a crafted NewInternalClient request, as exploi
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %100realtek · realtek sdk1 May 2015
- CVE-2021-2062135İzleyin
Cross-site request forgery (CSRF) vulnerability in Aterm WG2600HP firmware Ver1.0.2 and earlier, and Aterm WG2600HP2 firmware Ver1.0.2 and e
YüksekCVSS 8,8İstismar yokEPSS %1aterm · wg2600hp firmware28 Oca 2021
- CVE-2016-116835İzleyin
Cross-site request forgery (CSRF) vulnerability on NEC Aterm WF800HP devices with firmware 1.0.17 and earlier allows remote attackers to hij
YüksekCVSS 8,8İstismar yokEPSS %1aterm · wf800hp1 Nis 2016
- CVE-2016-116735İzleyin
Cross-site request forgery (CSRF) vulnerability on NEC Aterm WG300HP devices allows remote attackers to hijack the authentication of arbitra
YüksekCVSS 8,8İstismar yokEPSS %1aterm · wg300hp1 Nis 2016
- CVE-2017-1257531İzleyin
An issue was discovered on the NEC Aterm WG2600HP2 1.0.2.
YüksekCVSS 7,5İstismar yokEPSS %2aterm · wg2600hp2 firmware24 Ağu 2018
- CVE-2003-002431İzleyin
The menuBar feature in aterm 0.42 allows attackers to modify menu options and execute arbitrary commands via a certain character escape sequ
YüksekCVSS 7,5İstismar yokEPSS %2aterm · aterm3 Mar 2003
- CVE-2003-006731İzleyin
The aterm terminal emulator 0.42 allows attackers to modify the window title via a certain character escape sequence and then insert it back
YüksekCVSS 7,5İstismar yokEPSS %2aterm · aterm18 Mar 2003
- CVE-2021-2062024İzleyin
Cross-site scripting vulnerability in Aterm WF800HP firmware Ver1.0.9 and earlier allows remote attackers to inject an arbitrary script via
OrtaCVSS 6,1İstismar yokEPSS %1aterm · wg2600hp firmware28 Oca 2021
- CVE-2021-2062224İzleyin
Cross-site scripting vulnerability in Aterm WG2600HP firmware Ver1.0.2 and earlier, and Aterm WG2600HP2 firmware Ver1.0.2 and earlier allows
OrtaCVSS 6,1İstismar yokEPSS %1aterm · wg2600hp firmware28 Oca 2021
- CVE-2021-2071024İzleyin
Cross-site scripting vulnerability in Aterm WG2600HS firmware Ver1.5.1 and earlier allows remote attackers to inject an arbitrary script via
OrtaCVSS 6,1İstismar yokEPSS %1aterm · wg2600hs firmware25 Nis 2021
- CVE-2008-114214İzleyin
rxvt 2.6.4 opens a terminal window on :0 if the DISPLAY environment variable is not set, which might allow local users to hijack X11 connect
DüşükCVSS 3,7İstismar yokEPSS %0rxvt · rxvt7 Nis 2008