|
223251
|
8.8 |
HIGH
Network
|
totolink
|
a3002ru_firmware a702r_firmware n301rt_firmware n302r_firmware n300rt_firmware n200re_firmware n150rt_firmware n100re_firmware
|
On certain TOTOLINK Realtek SDK based routers, an authenticated attacker may execute arbitrary OS commands via the sysCmd parameter to the boafrm/formSysCmd URI, even if the GUI (syscmd.htm) is not a…
|
CWE-78
OS Command
|
CVE-2019-19824
|
2024-11-21 13:35 |
2020-01-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223252
|
7.5 |
HIGH
Network
|
totolink realtek sapido ciktel kctvjeju fg-products hiwifi tbroad coship iodata hcn_max-c300n_project
|
a3002ru_firmware a702r_firmware n302r_firmware n300rt_firmware n200re_firmware n150rt_firmware n100re_firmware rtk_11n_ap_firmware gr297n_firmware mesh_router_firmware w…
|
A certain router administration interface (that includes Realtek APMIB 0.11f for Boa 0.94.14rc21) stores cleartext administrative passwords in flash memory and in a file. This affects TOTOLINK A3002R…
|
CWE-522
Insufficiently Protected Credentials
|
CVE-2019-19823
|
2024-11-21 13:35 |
2020-01-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223253
|
7.5 |
HIGH
Network
|
totolink realtek sapido ciktel kctvjeju fg-products hiwifi tbroad coship iodata hcn_max-c300n_project
|
a3002ru_firmware a702r_firmware n302r_firmware n300rt_firmware n200re_firmware n150rt_firmware n100re_firmware rtk_11n_ap_firmware gr297n_firmware mesh_router_firmware w…
|
A certain router administration interface (that includes Realtek APMIB 0.11f for Boa 0.94.14rc21) allows remote attackers to retrieve the configuration, including sensitive data (usernames and passwo…
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2019-19822
|
2024-11-21 13:35 |
2020-01-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223254
|
9.8 |
CRITICAL
Network
|
totolink
|
a3002ru_firmware a702r_firmware n301rt_firmware n302r_firmware n300rt_firmware n200re_firmware n150rt_firmware n100re_firmware
|
On certain TOTOLINK Realtek SDK based routers, the CAPTCHA text can be retrieved via an {"topicurl":"setting/getSanvas"} POST to the boafrm/formLogin URI, leading to a CAPTCHA bypass. (Also, the CAPT…
|
CWE-287
Improper Authentication
|
CVE-2019-19825
|
2024-11-21 13:35 |
2020-01-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223255
|
8.8 |
HIGH
Network
|
bigswitch
|
big_cloud_fabric big_monitoring_fabric multi-cloud_director
|
An issue was discovered in Big Switch Big Monitoring Fabric 6.2 through 6.2.4, 6.3 through 6.3.9, 7.0 through 7.0.3, and 7.1 through 7.1.3; Big Cloud Fabric 4.5 through 4.5.5, 4.7 through 4.7.7, 5.0 …
|
CWE-200
Information Exposure
|
CVE-2019-19631
|
2024-11-21 13:35 |
2020-01-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223256
|
6.1 |
MEDIUM
Network
|
bigswitch
|
big_cloud_fabric big_monitoring_fabric multi-cloud_director
|
An issue was discovered in Big Switch Big Monitoring Fabric 6.2 through 6.2.4, 6.3 through 6.3.9, 7.0 through 7.0.3, and 7.1 through 7.1.3; Big Cloud Fabric 4.5 through 4.5.5, 4.7 through 4.7.7, 5.0 …
|
CWE-79
Cross-site Scripting
|
CVE-2019-19632
|
2024-11-21 13:35 |
2020-01-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223257
|
7.5 |
HIGH
Network
|
ixpdata
|
easyinstall
|
In IXP EasyInstall 6.2.13723, there are cleartext credentials in network communication on TCP port 20050 when using the Administrator console remotely.
|
CWE-319 CWE-522
Cleartext Transmission of Sensitive Information Insufficiently Protected Credentials
|
CVE-2019-19898
|
2024-11-21 13:35 |
2020-01-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223258
|
9.8 |
CRITICAL
Network
|
ixpdata
|
easyinstall
|
In IXP EasyInstall 6.2.13723, there is Remote Code Execution via the Agent Service. An unauthenticated attacker can communicate with the Agent Service over TCP port 20051, and execute code in the NT …
|
CWE-78
OS Command
|
CVE-2019-19897
|
2024-11-21 13:35 |
2020-01-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223259
|
9.9 |
CRITICAL
Network
|
ixpdata
|
easyinstall
|
In IXP EasyInstall 6.2.13723, there is Remote Code Execution via weak permissions on the Engine Service share. The default file permissions of the IXP$ share on the server allows modification of dire…
|
CWE-276
Incorrect Default Permissions
|
CVE-2019-19896
|
2024-11-21 13:35 |
2020-01-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223260
|
7.8 |
HIGH
Local
|
ixpdata
|
easyinstall
|
In IXP EasyInstall 6.2.13723, there is Lateral Movement (using the Agent Service) against other users on a client system. An authenticated attacker can, by modifying %SYSTEMDRIVE%\IXP\SW\[PACKAGE_COD…
|
CWE-732
Incorrect Permission Assignment for Critical Resource
|
CVE-2019-19895
|
2024-11-21 13:35 |
2020-01-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|