|
197721
|
8.8 |
HIGH
Network
|
draytek
|
vigorconnect
|
Draytek VigorConnect 1.6.0-B3 lacks cross-site request forgery protections and does not sufficiently verify whether a well-formed, valid, consistent request was intentionally provided by the user who…
|
CWE-352
Origin Validation Error
|
CVE-2021-20126
|
2024-11-21 14:45 |
2021-10-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197722
|
9.8 |
CRITICAL
Network
|
draytek
|
vigorconnect
|
An arbitrary file upload and directory traversal vulnerability exists in the file upload functionality of DownloadFileServlet in Draytek VigorConnect 1.6.0-B3. An unauthenticated attacker could lever…
|
CWE-22 CWE-434
Path Traversal Unrestricted Upload of File with Dangerous Type
|
CVE-2021-20125
|
2024-11-21 14:45 |
2021-10-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197723
|
7.5 |
HIGH
Network
|
draytek
|
vigorconnect
|
A local file inclusion vulnerability exists in Draytek VigorConnect 1.6.0-B3 in the file download functionality of the WebServlet endpoint. An unauthenticated attacker could leverage this vulnerabili…
|
CWE-22
Path Traversal
|
CVE-2021-20124
|
2024-11-21 14:45 |
2021-10-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197724
|
7.5 |
HIGH
Network
|
draytek
|
vigorconnect
|
A local file inclusion vulnerability exists in Draytek VigorConnect 1.6.0-B3 in the file download functionality of the DownloadFileServlet endpoint. An unauthenticated attacker could leverage this vu…
|
CWE-22
Path Traversal
|
CVE-2021-20123
|
2024-11-21 14:45 |
2021-10-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197725
|
6.1 |
MEDIUM
Network
|
sonicwall
|
sonicos
|
A Host Header Redirection vulnerability in SonicOS potentially allows a remote attacker to redirect firewall management users to arbitrary web domains.
|
CWE-601
Open Redirect
|
CVE-2021-20031
|
2024-11-21 14:45 |
2021-10-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197726
|
7.2 |
HIGH
Network
|
telus
|
prv65b444a-s-ts_firmware
|
The Telus Wi-Fi Hub (PRV65B444A-S-TS) with firmware version 3.00.20 is affected by an authenticated command injection vulnerability in multiple parameters passed to tr69_cmd.cgi. A remote attacker co…
|
CWE-78
OS Command
|
CVE-2021-20122
|
2024-11-21 14:45 |
2021-10-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197727
|
4.0 |
MEDIUM
Physics
|
telus
|
prv65b444a-s-ts_firmware
|
The Telus Wi-Fi Hub (PRV65B444A-S-TS) with firmware version 3.00.20 is vulnerable to an authenticated arbitrary file read. An authenticated user with physical access to the device can read arbitrary …
|
NVD-CWE-noinfo
|
CVE-2021-20121
|
2024-11-21 14:45 |
2021-10-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197728
|
6.5 |
MEDIUM
Network
|
sonicwall
|
sma_200_firmware sma_210_firmware sma_400_firmware sma_410_firmware sma_500v
|
Improper neutralization of special elements in the SMA100 management interface allows a remote authenticated attacker to inject arbitrary commands as a 'nobody' user which potentially leads to DoS.
|
CWE-78
OS Command
|
CVE-2021-20035
|
2024-11-21 14:45 |
2021-09-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197729
|
9.1 |
CRITICAL
Network
|
sonicwall
|
sma_200_firmware sma_210_firmware sma_400_firmware sma_410_firmware sma_500v
|
An improper access control vulnerability in SMA100 allows a remote unauthenticated attacker to bypass the path traversal checks and delete an arbitrary file potentially resulting in a reboot to facto…
|
CWE-22
Path Traversal
|
CVE-2021-20034
|
2024-11-21 14:45 |
2021-09-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197730
|
7.8 |
HIGH
Local
|
sonicwall
|
global_vpn_client
|
SonicWall Global VPN Client 4.10.5 installer (32-bit and 64-bit) incorrect default file permission vulnerability leads to privilege escalation which potentially allows command execution in the host o…
|
CWE-276
Incorrect Default Permissions
|
CVE-2021-20037
|
2024-11-21 14:45 |
2021-09-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|