|
197771
|
6.8 |
MEDIUM
Physics
|
netgear
|
rax43_firmware
|
Netgear RAX43 version 1.0.3.96 does not have sufficient protections to the UART interface. A malicious actor with physical access to the device is able to connect to the UART port via a serial connec…
|
CWE-287
Improper Authentication
|
CVE-2021-20168
|
2024-11-21 14:46 |
2021-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197772
|
8.0 |
HIGH
Adjacent
|
netgear
|
rax43_firmware
|
Netgear RAX43 version 1.0.3.96 contains a command injection vulnerability. The readycloud cgi application is vulnerable to command injection in the name parameter.
|
CWE-77
Command Injection
|
CVE-2021-20167
|
2024-11-21 14:46 |
2021-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197773
|
8.8 |
HIGH
Adjacent
|
netgear
|
rax43_firmware
|
Netgear RAX43 version 1.0.3.96 contains a buffer overrun vulnerability. The URL parsing functionality in the cgi-bin endpoint of the router containers a buffer overrun issue that can redirection cont…
|
CWE-120
Classic Buffer Overflow
|
CVE-2021-20166
|
2024-11-21 14:46 |
2021-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197774
|
8.8 |
HIGH
Network
|
trendnet
|
tew-827dru_firmware
|
Trendnet AC2600 TEW-827DRU version 2.08B01 does not properly implement csrf protections. Most pages lack proper usage of CSRF protections or mitigations. Additionally, pages that do make use of CSRF …
|
CWE-352
Origin Validation Error
|
CVE-2021-20165
|
2024-11-21 14:46 |
2021-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197775
|
4.9 |
MEDIUM
Network
|
trendnet
|
tew-827dru_firmware
|
Trendnet AC2600 TEW-827DRU version 2.08B01 improperly discloses credentials for the smb functionality of the device. Usernames and passwords for all smb users are revealed in plaintext on the smbserv…
|
CWE-522
Insufficiently Protected Credentials
|
CVE-2021-20164
|
2024-11-21 14:46 |
2021-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197776
|
4.9 |
MEDIUM
Network
|
trendnet
|
tew-827dru_firmware
|
Trendnet AC2600 TEW-827DRU version 2.08B01 leaks information via the ftp web page. Usernames and passwords for all ftp users are revealed in plaintext on the ftpserver.asp page.
|
CWE-522
Insufficiently Protected Credentials
|
CVE-2021-20163
|
2024-11-21 14:46 |
2021-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197777
|
4.9 |
MEDIUM
Network
|
trendnet
|
tew-827dru_firmware
|
Trendnet AC2600 TEW-827DRU version 2.08B01 stores credentials in plaintext. Usernames and passwords are stored in plaintext in the config files on the device. For example, /etc/config/cameo contains …
|
CWE-312
Cleartext Storage of Sensitive Information
|
CVE-2021-20162
|
2024-11-21 14:46 |
2021-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197778
|
6.8 |
MEDIUM
Physics
|
trendnet
|
tew-827dru_firmware
|
Trendnet AC2600 TEW-827DRU version 2.08B01 does not have sufficient protections for the UART functionality. A malicious actor with physical access to the device is able to connect to the UART port vi…
|
CWE-287 CWE-306
Improper Authentication Missing Authentication for Critical Function
|
CVE-2021-20161
|
2024-11-21 14:46 |
2021-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197779
|
8.8 |
HIGH
Network
|
trendnet
|
tew-827dru_firmware
|
Trendnet AC2600 TEW-827DRU version 2.08B01 contains a command injection vulnerability in the smb functionality of the device. The username parameter used when configuring smb functionality for the de…
|
CWE-78
OS Command
|
CVE-2021-20160
|
2024-11-21 14:46 |
2021-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197780
|
8.8 |
HIGH
Network
|
trendnet
|
tew-827dru_firmware
|
Trendnet AC2600 TEW-827DRU version 2.08B01 is vulnerable to command injection. The system log functionality of the firmware allows for command injection as root by supplying a malformed parameter.
|
CWE-78
OS Command
|
CVE-2021-20159
|
2024-11-21 14:46 |
2021-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|