|
199951
|
6.5 |
MEDIUM
Adjacent
|
netgear
|
gs116e_firmware jgs516pe_firmware
|
The TFTP server fails to handle multiple connections on NETGEAR JGS516PE/GS116Ev2 v2.6.0.43 devices, and allows external attackers to force device reboots by sending concurrent connections, aka a den…
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2020-35233
|
2024-11-21 14:27 |
2021-03-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199952
|
8.8 |
HIGH
Adjacent
|
netgear
|
gs116e_firmware jgs516pe_firmware
|
The NSDP protocol implementation on NETGEAR JGS516PE/GS116Ev2 v2.6.0.43 devices was affected by an authentication issue that allows an attacker to bypass access controls and obtain full control of th…
|
CWE-287
Improper Authentication
|
CVE-2020-35231
|
2024-11-21 14:27 |
2021-03-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199953
|
6.8 |
MEDIUM
Adjacent
|
netgear
|
gs116e_firmware jgs516pe_firmware
|
Multiple integer overflow parameters were found in the web administration panel on NETGEAR JGS516PE/GS116Ev2 v2.6.0.43 devices. Most of the integer parameters sent through the web server can be abuse…
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2020-35230
|
2024-11-21 14:27 |
2021-03-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199954
|
8.8 |
HIGH
Adjacent
|
netgear
|
gs116e_firmware jgs516pe_firmware
|
The authentication token required to execute NSDP write requests on NETGEAR JGS516PE/GS116Ev2 v2.6.0.43 devices is not properly invalidated and can be reused until a new token is generated, which all…
|
CWE-384
Session Fixation
|
CVE-2020-35229
|
2024-11-21 14:27 |
2021-03-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199955
|
4.8 |
MEDIUM
Network
|
netgear
|
gs116e_firmware jgs516pe_firmware
|
A cross-site scripting (XSS) vulnerability in the administration web panel on NETGEAR JGS516PE/GS116Ev2 v2.6.0.43 devices allows remote attackers to inject arbitrary web script or HTML via the langua…
|
CWE-79
Cross-site Scripting
|
CVE-2020-35228
|
2024-11-21 14:27 |
2021-03-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199956
|
7.2 |
HIGH
Network
|
netgear
|
gs116e_firmware jgs516pe_firmware
|
A buffer overflow vulnerability in the access control section on NETGEAR JGS516PE/GS116Ev2 v2.6.0.43 devices (in the administration web panel) allows an attacker to inject IP addresses into the white…
|
CWE-120
Classic Buffer Overflow
|
CVE-2020-35227
|
2024-11-21 14:27 |
2021-03-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199957
|
7.1 |
HIGH
Adjacent
|
netgear
|
gs116e_firmware jgs516pe_firmware
|
NETGEAR JGS516PE/GS116Ev2 v2.6.0.43 devices allow unauthenticated users to modify the switch DHCP configuration by sending the corresponding write request command.
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2020-35226
|
2024-11-21 14:27 |
2021-03-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199958
|
6.8 |
MEDIUM
Adjacent
|
netgear
|
gs116e_firmware jgs516pe_firmware
|
The NSDP protocol implementation on NETGEAR JGS516PE/GS116Ev2 v2.6.0.43 devices was not properly validating the length of string parameters sent in write requests, potentially allowing denial of serv…
|
CWE-120
Classic Buffer Overflow
|
CVE-2020-35225
|
2024-11-21 14:27 |
2021-03-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199959
|
6.5 |
MEDIUM
Adjacent
|
netgear
|
gs116e_firmware jgs516pe_firmware
|
A buffer overflow vulnerability in the NSDP protocol authentication method on NETGEAR JGS516PE/GS116Ev2 v2.6.0.43 devices allows remote unauthenticated attackers to force a device reboot.
|
CWE-120
Classic Buffer Overflow
|
CVE-2020-35224
|
2024-11-21 14:27 |
2021-03-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199960
|
8.8 |
HIGH
Network
|
netgear
|
gs116e_firmware jgs516pe_firmware
|
The CSRF protection mechanism implemented in the web administration panel on NETGEAR JGS516PE/GS116Ev2 v2.6.0.43 devices could be bypassed by omitting the CSRF token parameter in HTTP requests.
|
CWE-352
Origin Validation Error
|
CVE-2020-35223
|
2024-11-21 14:27 |
2021-03-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|