Mercusys kayıtları
mercusys üreticisine ait 9 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 0
- Düzeltme kaydı olan
- %0
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')2
- CWE-787 Out-of-bounds Write2
- CWE-121 Stack-based Buffer Overflow1
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor1
- CWE-755 Improper Handling of Exceptional Conditions1
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
9 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
31İzleyin | CVE-2022-26988İstismar yok | TP-Link TL-WDR7660 2.0.30, Mercury D196G 20200109_2.0.4, and Fast FAC1900R 20190827_2.0.2 routers have a stack overflow issue in `MntAte` futp-link · tl-wdr7660 firmware · CWE-787 | Yüksek7,8 | — | %1,5 | 10 May 2022 |
31İzleyin | CVE-2022-26987İstismar yok | TP-Link TL-WDR7660 2.0.30, Mercury D196G 20200109_2.0.4, and Fast FAC1900R 20190827_2.0.2 routers have a stack overflow issue in `MmtAtePrastp-link · tl-wdr7660 firmware · CWE-787 | Yüksek7,8 | — | %1,5 | 10 May 2022 |
30İzleyin | CVE-2021-25811İstismar yok | MERCUSYS Mercury X18G 1.0.5 devices allow Denial of service via a crafted value to the POST listen_http_lan parameter.mercusys · mercury x18g firmware | Yüksek7,5 | — | %1,6 | 29 Nis 2021 |
27İzleyin | CVE-2025-56463İstismar yok | Mercusys MW305R 3.30 and below is has a Transport Layer Security (TLS) certificate private key disclosure.mercusys · mw305r firmware · CWE-200 | Orta6,8 | — | %0,2 | 26 Eyl 2025 |
26İzleyin | CVE-2023-52162İstismar yok | Mercusys MW325R EU V3 (Firmware MW325R(EU)_V3_1.11.0 Build 221019) is vulnerable to a stack-based buffer overflow, which could allow an attaCWE-121 | Orta6,7 | — | %0,6 | 3 Haz 2024 |
25İzleyin | CVE-2021-23241Kavram kanıtı | MERCUSYS Mercury X18G 1.0.5 devices allow Directory Traversal via ../ in conjunction with a loginLess or login.htm URI (for authentication bmercusys · mercury x18g firmware · CWE-22 | Orta5,3 | — | %13,3 | 7 Oca 2021 |
24İzleyin | CVE-2021-25810İstismar yok | Cross site Scripting (XSS) vulnerability in MERCUSYS Mercury X18G 1.0.5 devices, via crafted values to the 'src_dport_start', 'src_dport_endmercusys · mercury x18g firmware · CWE-79 | Orta6,1 | — | %1,1 | 29 Nis 2021 |
22İzleyin | CVE-2021-23242İstismar yok | MERCUSYS Mercury X18G 1.0.5 devices allow Directory Traversal via ../ to the UPnP server, as demonstrated by the /../../conf/template/uhttpdmercusys · mercury x18g firmware · CWE-22 | Orta5,3 | — | %1,8 | 7 Oca 2021 |
20İzleyin | CVE-2023-46297İstismar yok | An issue was discovered on Mercusys MW325R EU V3 MW325R(EU)_V3_1.11.0 221019 devices.CWE-755 | Orta5,1 | — | %0,2 | 29 May 2024 |
- CVE-2022-2698831İzleyin
TP-Link TL-WDR7660 2.0.30, Mercury D196G 20200109_2.0.4, and Fast FAC1900R 20190827_2.0.2 routers have a stack overflow issue in `MntAte` fu
YüksekCVSS 7,8İstismar yokEPSS %2tp-link · tl-wdr7660 firmware10 May 2022
- CVE-2022-2698731İzleyin
TP-Link TL-WDR7660 2.0.30, Mercury D196G 20200109_2.0.4, and Fast FAC1900R 20190827_2.0.2 routers have a stack overflow issue in `MmtAtePras
YüksekCVSS 7,8İstismar yokEPSS %2tp-link · tl-wdr7660 firmware10 May 2022
- CVE-2021-2581130İzleyin
MERCUSYS Mercury X18G 1.0.5 devices allow Denial of service via a crafted value to the POST listen_http_lan parameter.
YüksekCVSS 7,5İstismar yokEPSS %2mercusys · mercury x18g firmware29 Nis 2021
- CVE-2025-5646327İzleyin
Mercusys MW305R 3.30 and below is has a Transport Layer Security (TLS) certificate private key disclosure.
OrtaCVSS 6,8İstismar yokEPSS %0mercusys · mw305r firmware26 Eyl 2025
- CVE-2023-5216226İzleyin
Mercusys MW325R EU V3 (Firmware MW325R(EU)_V3_1.11.0 Build 221019) is vulnerable to a stack-based buffer overflow, which could allow an atta
OrtaCVSS 6,7İstismar yokEPSS %13 Haz 2024
- CVE-2021-2324125İzleyin
MERCUSYS Mercury X18G 1.0.5 devices allow Directory Traversal via ../ in conjunction with a loginLess or login.htm URI (for authentication b
OrtaCVSS 5,3Kavram kanıtıEPSS %13mercusys · mercury x18g firmware7 Oca 2021
- CVE-2021-2581024İzleyin
Cross site Scripting (XSS) vulnerability in MERCUSYS Mercury X18G 1.0.5 devices, via crafted values to the 'src_dport_start', 'src_dport_end
OrtaCVSS 6,1İstismar yokEPSS %1mercusys · mercury x18g firmware29 Nis 2021
- CVE-2021-2324222İzleyin
MERCUSYS Mercury X18G 1.0.5 devices allow Directory Traversal via ../ to the UPnP server, as demonstrated by the /../../conf/template/uhttpd
OrtaCVSS 5,3İstismar yokEPSS %2mercusys · mercury x18g firmware7 Oca 2021
- CVE-2023-4629720İzleyin
An issue was discovered on Mercusys MW325R EU V3 MW325R(EU)_V3_1.11.0 221019 devices.
OrtaCVSS 5,1İstismar yokEPSS %029 May 2024