iball kayıtları
iball üreticisine ait 9 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 0
- Düzeltme kaydı olan
- %0
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-352 Cross-Site Request Forgery (CSRF)2
- CWE-798 Use of Hard-coded Credentials2
- CWE-312 Cleartext Storage of Sensitive Information1
- CWE-425 Direct Request ('Forced Browsing')1
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')1
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
9 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
44Planlayın | CVE-2017-14244Kavram kanıtı | An authentication bypass vulnerability on iBall Baton ADSL2+ Home Router FW_iB-LR7011A_1.0.2 devices potentially allows attackers to directliball · ib-wra150n firmware · CWE-425 | Kritik9,8 | — | %17,1 | 17 Eyl 2017 |
44Planlayın | CVE-2017-6558Kavram kanıtı | iball Baton 150M iB-WRA150N v1 00000001 1.2.6 build 110401 Rel.47776n devices are prone to an authentication bypass vulnerability that allowiball · ib-wra150n firmware · CWE-798 | Kritik9,8 | — | %15,3 | 9 Mar 2017 |
40Planlayın | CVE-2018-6387İstismar yok | iBall iB-WRA150N 1.2.6 build 110401 Rel.47776n devices have a hardcoded password of admin for the admin account, a hardcoded password of supiball · ib-wra150n firmware · CWE-798 | Kritik9,8 | — | %1,8 | 29 Oca 2018 |
37İzleyin | CVE-2018-6388Kavram kanıtı | iBall iB-WRA150N 1.2.6 build 110401 Rel.47776n devices allow remote authenticated users to execute arbitrary OS commands via shell metacharaiball · ib-wra150n firmware · CWE-78 | Yüksek8,8 | — | %5,9 | 29 Oca 2018 |
36İzleyin | CVE-2017-11169İstismar yok | Privilege Escalation on iBall iB-WRA300N3GT iB-WRA300N3GT_1.1.1 devices allows remote authenticated users to obtain root privileges by leveriball · ib-wra300n3gt firmware | Yüksek8,8 | — | %2,2 | 13 Kas 2017 |
27İzleyin | CVE-2018-20008İstismar yok | iBall Baton iB-WRB302N20122017 devices have improper access control over the UART interface, allowing physical attackers to discover Wi-Fi ciball · ib-wrb302n firmware · CWE-312 | Orta6,8 | — | %0,3 | 28 May 2019 |
26İzleyin | CVE-2020-15043İstismar yok | iBall WRB303N devices allow CSRF attacks, as demonstrated by enabling remote management, enabling DHCP, or modifying the subnet range for IPiball · wrb303n firmware · CWE-352 | Orta6,5 | — | %0,4 | 29 Haz 2020 |
26İzleyin | CVE-2020-29292İstismar yok | iBall WRD12EN 1.0.0 devices allow cross-site request forgery (CSRF) attacks as demonstrated by enabling DNS settings or modifying the range iball · wrd12en firmware · CWE-352 | Orta6,5 | — | %0,4 | 30 Ara 2021 |
24İzleyin | CVE-2018-6355İstismar yok | /goform/setLang on iBall 300M devices with "iB-WRB302N_1.0.1-Sep 8 2017" firmware has Unauthenticated Stored Cross Site Scripting via the laiball · ib-wrb302n firmware · CWE-79 | Orta6,1 | — | %0,6 | 30 Oca 2018 |
- CVE-2017-1424444Planlayın
An authentication bypass vulnerability on iBall Baton ADSL2+ Home Router FW_iB-LR7011A_1.0.2 devices potentially allows attackers to directl
KritikCVSS 9,8Kavram kanıtıEPSS %17iball · ib-wra150n firmware17 Eyl 2017
- CVE-2017-655844Planlayın
iball Baton 150M iB-WRA150N v1 00000001 1.2.6 build 110401 Rel.47776n devices are prone to an authentication bypass vulnerability that allow
KritikCVSS 9,8Kavram kanıtıEPSS %15iball · ib-wra150n firmware9 Mar 2017
- CVE-2018-638740Planlayın
iBall iB-WRA150N 1.2.6 build 110401 Rel.47776n devices have a hardcoded password of admin for the admin account, a hardcoded password of sup
KritikCVSS 9,8İstismar yokEPSS %2iball · ib-wra150n firmware29 Oca 2018
- CVE-2018-638837İzleyin
iBall iB-WRA150N 1.2.6 build 110401 Rel.47776n devices allow remote authenticated users to execute arbitrary OS commands via shell metachara
YüksekCVSS 8,8Kavram kanıtıEPSS %6iball · ib-wra150n firmware29 Oca 2018
- CVE-2017-1116936İzleyin
Privilege Escalation on iBall iB-WRA300N3GT iB-WRA300N3GT_1.1.1 devices allows remote authenticated users to obtain root privileges by lever
YüksekCVSS 8,8İstismar yokEPSS %2iball · ib-wra300n3gt firmware13 Kas 2017
- CVE-2018-2000827İzleyin
iBall Baton iB-WRB302N20122017 devices have improper access control over the UART interface, allowing physical attackers to discover Wi-Fi c
OrtaCVSS 6,8İstismar yokEPSS %0iball · ib-wrb302n firmware28 May 2019
- CVE-2020-1504326İzleyin
iBall WRB303N devices allow CSRF attacks, as demonstrated by enabling remote management, enabling DHCP, or modifying the subnet range for IP
OrtaCVSS 6,5İstismar yokEPSS %0iball · wrb303n firmware29 Haz 2020
- CVE-2020-2929226İzleyin
iBall WRD12EN 1.0.0 devices allow cross-site request forgery (CSRF) attacks as demonstrated by enabling DNS settings or modifying the range
OrtaCVSS 6,5İstismar yokEPSS %0iball · wrd12en firmware30 Ara 2021
- CVE-2018-635524İzleyin
/goform/setLang on iBall 300M devices with "iB-WRB302N_1.0.1-Sep 8 2017" firmware has Unauthenticated Stored Cross Site Scripting via the la
OrtaCVSS 6,1İstismar yokEPSS %1iball · ib-wrb302n firmware30 Oca 2018