netis-systems kayıtları
netis-systems üreticisine ait 51 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 1 · %2
- Silahlaştırılmış
- 2 · %3,9
- Pre-auth RCE
- 12
- Düzeltme kaydı olan
- %2
- Yayından KEV’e ortanca
- 635 gün
Tekrar eden sınıflar
- CWE-120 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')11
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')10
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')8
- CWE-77 Improper Neutralization of Special Elements used in a Command ('Command Injection')6
- CWE-476 NULL Pointer Dereference2
- CWE-352 Cross-Site Request Forgery (CSRF)2
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
51 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
68Bu hafta | CVE-2019-19356Silahlaştırılmış | Netis WF2419 is vulnerable to authenticated Remote Code Execution (RCE) as root through the router Web management page.netis-systems · wf2419 firmware · CWE-78 | Yüksek7,5 | KEV | %28,2 | 7 Şub 2020 |
60Bu hafta | CVE-2024-22729Silahlaştırılmış | NETIS SYSTEMS MW5360 V1.0.1.3031 was discovered to contain a command injection vulnerability via the password parameter on the login page.netis-systems · mw5360 firmware · CWE-77 | Kritik9,8 | — | %70,8 | 25 Oca 2024 |
55Planlayın | CVE-2021-26747İstismar yok | Netis WF2780 2.3.40404 and WF2411 1.1.29629 devices allow Shell Metacharacter Injection into the ping command, leading to remote code executnetis-systems · wf2780 firmware · CWE-78 | Kritik9,8 | — | %54,8 | 18 Şub 2021 |
45Planlayın | CVE-2024-25850İstismar yok | Netis WF2780 v2.1.40144 was discovered to contain a command injection vulnerability via the wps_ap_ssid5g parameternetis-systems · wf2780 firmware · CWE-77 | Kritik9,8 | — | %19,1 | 22 Şub 2024 |
43Planlayın | CVE-2019-8985Kavram kanıtı | On Netis WF2411 with firmware 2.1.36123 and other Netis WF2xxx devices (possibly WF2411 through WF2880), there is a stack-based buffer overfnetis-systems · wf2411 firmware · CWE-306 | Kritik9,8 | — | %13,3 | 21 Şub 2019 |
40Planlayın | CVE-2023-45466İstismar yok | Netis N3Mv2-V1.0.1.865 was discovered to contain a command injection vulnerability via the pin_host parameter in the WPS Settings.netis-systems · n3mv2 firmware · CWE-77 | Kritik9,8 | — | %1,9 | 13 Eki 2023 |
40Planlayın | CVE-2023-45467İstismar yok | Netis N3Mv2-V1.0.1.865 was discovered to contain a command injection vulnerability via the ntpServIP parameter in the Time Settings.netis-systems · n3m firmware · CWE-78 | Kritik9,8 | — | %1,9 | 13 Eki 2023 |
40Planlayın | CVE-2023-43892İstismar yok | Netis N3Mv2-V1.0.1.865 was discovered to contain a command injection vulnerability via the Hostname parameter within the WAN settings.netis-systems · n3m firmware · CWE-78 | Kritik9,8 | — | %1,9 | 2 Eki 2023 |
40Planlayın | CVE-2023-43891İstismar yok | Netis N3Mv2-V1.0.1.865 was discovered to contain a command injection vulnerability in the Changing Username and Password function.netis-systems · n3m firmware · CWE-77 | Kritik9,8 | — | %1,9 | 2 Eki 2023 |
40Planlayın | CVE-2023-43893İstismar yok | Netis N3Mv2-V1.0.1.865 was discovered to contain a command injection vulnerability via the wakeup_mac parameter in the Wake-On-LAN (WoL) funnetis-systems · n3m firmware · CWE-78 | Kritik9,8 | — | %1,9 | 2 Eki 2023 |
40Planlayın | CVE-2023-45465İstismar yok | Netis N3Mv2-V1.0.1.865 was discovered to contain a command injection vulnerability via the ddnsDomainName parameter in the Dynamic DNS settinetis-systems · n3m firmware · CWE-77 | Kritik9,8 | — | %1,8 | 13 Eki 2023 |
39İzleyin | CVE-2023-42336İstismar yok | An issue in NETIS SYSTEMS WF2409Ev4 v.1.0.1.705 allows a remote attacker to execute arbitrary code and obtain sensitive information via the netis-systems · wf2409e firmware · CWE-798 | Kritik9,8 | — | %1,3 | 15 Eyl 2023 |
39İzleyin | CVE-2024-33792İstismar yok | netis-systems MEX605 v2.00.06 allows attackers to execute arbitrary OS commands via a crafted payload to the tracert page.netis-systems · mex605 firmware · CWE-78 | Kritik9,8 | — | %1,0 | 3 May 2024 |
39İzleyin | CVE-2023-43134İstismar yok | There is an unauthorized access vulnerability in Netis 360RAC1200 v1.3.4517, which allows attackers to obtain sensitive information of the dnetis-systems · 360r firmware · CWE-862 | Kritik9,8 | — | %0,9 | 20 Eyl 2023 |
39İzleyin | CVE-2018-25069İstismar yok | Netis Netcore Router hard-coded passwordnetis-systems · netcore router firmware · CWE-259 | Kritik9,8 | — | %0,9 | 7 Oca 2023 |
36İzleyin | CVE-2023-44860İstismar yok | An issue in NETIS SYSTEMS N3Mv2 v.1.0.1.865 allows a remote attacker to cause a denial of service via the authorization component in the HTTnetis-systems · n3m firmware · CWE-863 | Yüksek7,5 | — | %19,5 | 6 Eki 2023 |
36İzleyin | CVE-2023-43890İstismar yok | Netis N3Mv2-V1.0.1.865 was discovered to contain a command injection vulnerability in the diagnostic tools page.netis-systems · n3m firmware · CWE-78 | Yüksek8,8 | — | %2,5 | 2 Eki 2023 |
36İzleyin | CVE-2023-38829Kavram kanıtı | An issue in NETIS SYSTEMS WF2409E v.3.6.42541 allows a remote attacker to execute arbitrary code via the ping and traceroute functions of thnetis-systems · wf2409e firmware · CWE-77 | Yüksek8,8 | — | %2,4 | 11 Eyl 2023 |
36İzleyin | CVE-2020-8946İstismar yok | Netis WF2471 v1.2.30142 devices allow an authenticated attacker to execute arbitrary OS commands via shell metacharacters in the /cgi-bin-ignetis-systems · wf2471 firmware · CWE-78 | Yüksek8,8 | — | %1,9 | 12 Şub 2020 |
35İzleyin | CVE-2019-20074İstismar yok | On Netis DL4323 devices, any user role can view sensitive information, such as a user password or the FTP password, via the form2saveConf.cgnetis-systems · dl4343 firmware · CWE-269 | Yüksek8,8 | — | %1,4 | 29 Ara 2019 |
35İzleyin | CVE-2018-6391İstismar yok | A cross-site request forgery web vulnerability has been discovered on Netis WF2419 V2.2.36123 devices.netis-systems · wf2419 firmware · CWE-352 | Yüksek8,8 | — | %1,0 | 29 Oca 2018 |
33İzleyin | CVE-2024-25851İstismar yok | Netis WF2780 v2.1.40144 was discovered to contain a command injection vulnerability via the config_sequence parameter in other_para of cgitenetis-systems · wf2780 firmware · CWE-78 | Yüksek8,0 | — | %1,9 | 22 Şub 2024 |
30İzleyin | CVE-2023-0113İstismar yok | Netis Netcore Router Backup param.file.tgz information disclosurenetis-systems · netcore router firmware · CWE-200 | Yüksek7,5 | — | %0,8 | 7 Oca 2023 |
30İzleyin | CVE-2023-45468İstismar yok | Netis N3Mv2-V1.0.1.865 was discovered to contain a buffer overflow via the pingWdogIp.netis-systems · n3m firmware · CWE-120 | Yüksek7,5 | — | %0,7 | 13 Eki 2023 |
30İzleyin | CVE-2023-45463İstismar yok | Netis N3Mv2-V1.0.1.865 was discovered to contain a buffer overflow via the hostName parameter in the FUN_0040dabc function.netis-systems · n3m firmware · CWE-120 | Yüksek7,5 | — | %0,6 | 13 Eki 2023 |
- CVE-2019-1935668Bu hafta
Netis WF2419 is vulnerable to authenticated Remote Code Execution (RCE) as root through the router Web management page.
YüksekCVSS 7,5KEVSilahlaştırılmışEPSS %28netis-systems · wf2419 firmware7 Şub 2020
- CVE-2024-2272960Bu hafta
NETIS SYSTEMS MW5360 V1.0.1.3031 was discovered to contain a command injection vulnerability via the password parameter on the login page.
KritikCVSS 9,8SilahlaştırılmışEPSS %71netis-systems · mw5360 firmware25 Oca 2024
- CVE-2021-2674755Planlayın
Netis WF2780 2.3.40404 and WF2411 1.1.29629 devices allow Shell Metacharacter Injection into the ping command, leading to remote code execut
KritikCVSS 9,8İstismar yokEPSS %55netis-systems · wf2780 firmware18 Şub 2021
- CVE-2024-2585045Planlayın
Netis WF2780 v2.1.40144 was discovered to contain a command injection vulnerability via the wps_ap_ssid5g parameter
KritikCVSS 9,8İstismar yokEPSS %19netis-systems · wf2780 firmware22 Şub 2024
- CVE-2019-898543Planlayın
On Netis WF2411 with firmware 2.1.36123 and other Netis WF2xxx devices (possibly WF2411 through WF2880), there is a stack-based buffer overf
KritikCVSS 9,8Kavram kanıtıEPSS %13netis-systems · wf2411 firmware21 Şub 2019
- CVE-2023-4546640Planlayın
Netis N3Mv2-V1.0.1.865 was discovered to contain a command injection vulnerability via the pin_host parameter in the WPS Settings.
KritikCVSS 9,8İstismar yokEPSS %2netis-systems · n3mv2 firmware13 Eki 2023
- CVE-2023-4546740Planlayın
Netis N3Mv2-V1.0.1.865 was discovered to contain a command injection vulnerability via the ntpServIP parameter in the Time Settings.
KritikCVSS 9,8İstismar yokEPSS %2netis-systems · n3m firmware13 Eki 2023
- CVE-2023-4389240Planlayın
Netis N3Mv2-V1.0.1.865 was discovered to contain a command injection vulnerability via the Hostname parameter within the WAN settings.
KritikCVSS 9,8İstismar yokEPSS %2netis-systems · n3m firmware2 Eki 2023
- CVE-2023-4389140Planlayın
Netis N3Mv2-V1.0.1.865 was discovered to contain a command injection vulnerability in the Changing Username and Password function.
KritikCVSS 9,8İstismar yokEPSS %2netis-systems · n3m firmware2 Eki 2023
- CVE-2023-4389340Planlayın
Netis N3Mv2-V1.0.1.865 was discovered to contain a command injection vulnerability via the wakeup_mac parameter in the Wake-On-LAN (WoL) fun
KritikCVSS 9,8İstismar yokEPSS %2netis-systems · n3m firmware2 Eki 2023
- CVE-2023-4546540Planlayın
Netis N3Mv2-V1.0.1.865 was discovered to contain a command injection vulnerability via the ddnsDomainName parameter in the Dynamic DNS setti
KritikCVSS 9,8İstismar yokEPSS %2netis-systems · n3m firmware13 Eki 2023
- CVE-2023-4233639İzleyin
An issue in NETIS SYSTEMS WF2409Ev4 v.1.0.1.705 allows a remote attacker to execute arbitrary code and obtain sensitive information via the
KritikCVSS 9,8İstismar yokEPSS %1netis-systems · wf2409e firmware15 Eyl 2023
- CVE-2024-3379239İzleyin
netis-systems MEX605 v2.00.06 allows attackers to execute arbitrary OS commands via a crafted payload to the tracert page.
KritikCVSS 9,8İstismar yokEPSS %1netis-systems · mex605 firmware3 May 2024
- CVE-2023-4313439İzleyin
There is an unauthorized access vulnerability in Netis 360RAC1200 v1.3.4517, which allows attackers to obtain sensitive information of the d
KritikCVSS 9,8İstismar yokEPSS %1netis-systems · 360r firmware20 Eyl 2023
- CVE-2018-2506939İzleyin
Netis Netcore Router hard-coded password
KritikCVSS 9,8İstismar yokEPSS %1netis-systems · netcore router firmware7 Oca 2023
- CVE-2023-4486036İzleyin
An issue in NETIS SYSTEMS N3Mv2 v.1.0.1.865 allows a remote attacker to cause a denial of service via the authorization component in the HTT
YüksekCVSS 7,5İstismar yokEPSS %20netis-systems · n3m firmware6 Eki 2023
- CVE-2023-4389036İzleyin
Netis N3Mv2-V1.0.1.865 was discovered to contain a command injection vulnerability in the diagnostic tools page.
YüksekCVSS 8,8İstismar yokEPSS %3netis-systems · n3m firmware2 Eki 2023
- CVE-2023-3882936İzleyin
An issue in NETIS SYSTEMS WF2409E v.3.6.42541 allows a remote attacker to execute arbitrary code via the ping and traceroute functions of th
YüksekCVSS 8,8Kavram kanıtıEPSS %2netis-systems · wf2409e firmware11 Eyl 2023
- CVE-2020-894636İzleyin
Netis WF2471 v1.2.30142 devices allow an authenticated attacker to execute arbitrary OS commands via shell metacharacters in the /cgi-bin-ig
YüksekCVSS 8,8İstismar yokEPSS %2netis-systems · wf2471 firmware12 Şub 2020
- CVE-2019-2007435İzleyin
On Netis DL4323 devices, any user role can view sensitive information, such as a user password or the FTP password, via the form2saveConf.cg
YüksekCVSS 8,8İstismar yokEPSS %1netis-systems · dl4343 firmware29 Ara 2019
- CVE-2018-639135İzleyin
A cross-site request forgery web vulnerability has been discovered on Netis WF2419 V2.2.36123 devices.
YüksekCVSS 8,8İstismar yokEPSS %1netis-systems · wf2419 firmware29 Oca 2018
- CVE-2024-2585133İzleyin
Netis WF2780 v2.1.40144 was discovered to contain a command injection vulnerability via the config_sequence parameter in other_para of cgite
YüksekCVSS 8,0İstismar yokEPSS %2netis-systems · wf2780 firmware22 Şub 2024
- CVE-2023-011330İzleyin
Netis Netcore Router Backup param.file.tgz information disclosure
YüksekCVSS 7,5İstismar yokEPSS %1netis-systems · netcore router firmware7 Oca 2023
- CVE-2023-4546830İzleyin
Netis N3Mv2-V1.0.1.865 was discovered to contain a buffer overflow via the pingWdogIp.
YüksekCVSS 7,5İstismar yokEPSS %1netis-systems · n3m firmware13 Eki 2023
- CVE-2023-4546330İzleyin
Netis N3Mv2-V1.0.1.865 was discovered to contain a buffer overflow via the hostName parameter in the FUN_0040dabc function.
YüksekCVSS 7,5İstismar yokEPSS %1netis-systems · n3m firmware13 Eki 2023