|
200121
|
7.8 |
HIGH
Local
|
qualcomm
|
ar8031_firmware ar8035_firmware csra6620_firmware csra6640_firmware csrb31024_firmware fsm10055_firmware fsm10056_firmware mdm9150_firmware mdm9205_firmware mdm9628_firmwar…
|
Improper access control in TrustZone due to improper error handling while handling the signing key in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon…
|
CWE-755
Improper Handling of Exceptional Conditions
|
CVE-2021-1894
|
2024-11-21 14:45 |
2022-01-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
200122
|
8.8 |
HIGH
Adjacent
|
dlink
|
dir-2640-us_firmware
|
Quagga Services on D-Link DIR-2640 less than or equal to version 1.11B02 use default hard-coded credentials, which can allow a remote attacker to gain administrative access to the zebra or ripd those…
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2021-20132
|
2024-11-21 14:45 |
2021-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
200123
|
8.4 |
HIGH
Adjacent
|
dlink
|
dir-2640-us_firmware
|
Quagga Services on D-Link DIR-2640 less than or equal to version 1.11B02 are affected by an absolute path traversal vulnerability that allows a remote, authenticated attacker to set an arbitrary file…
|
CWE-22
Path Traversal
|
CVE-2021-20134
|
2024-11-21 14:45 |
2021-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
200124
|
6.1 |
MEDIUM
Adjacent
|
dlink
|
dir-2640-us_firmware
|
Quagga Services on D-Link DIR-2640 less than or equal to version 1.11B02 are affected by an absolute path traversal vulnerability that allows a remote, authenticated attacker to set the "message of t…
|
CWE-22
Path Traversal
|
CVE-2021-20133
|
2024-11-21 14:45 |
2021-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
200125
|
7.5 |
HIGH
Network
|
sonicwall
|
sma_100_firmware sma_200_firmware sma_210_firmware sma_400_firmware sma_410_firmware sma_500v_firmware
|
An Improper Access Control Vulnerability in the SMA100 series leads to multiple restricted management APIs being accessible without a user login, potentially exposing configuration meta-data.
|
NVD-CWE-Other
|
CVE-2021-20050
|
2024-11-21 14:45 |
2021-12-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
200126
|
7.5 |
HIGH
Network
|
sonicwall
|
sma_100_firmware sma_200_firmware sma_210_firmware sma_400_firmware sma_410_firmware sma_500v_firmware
|
A vulnerability in SonicWall SMA100 password change API allows a remote unauthenticated attacker to perform SMA100 username enumeration based on the server responses. This vulnerability impacts 10.2.…
|
CWE-203
Information Exposure Through Discrepancy
|
CVE-2021-20049
|
2024-11-21 14:45 |
2021-12-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
200127
|
8.8 |
HIGH
Adjacent
|
gryphonconnect
|
gryphon_tower_firmware
|
An unauthenticated command injection vulnerability exists in the parameters of operation 3 in the controller_server service on Gryphon Tower routers. An unauthenticated remote attacker on the same ne…
|
CWE-78
OS Command
|
CVE-2021-20139
|
2024-11-21 14:45 |
2021-12-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
200128
|
8.8 |
HIGH
Adjacent
|
gryphonconnect
|
gryphon_tower_firmware
|
An unauthenticated command injection vulnerability exists in multiple parameters in the Gryphon Tower router’s web interface at /cgi-bin/luci/rc. An unauthenticated remote attacker on the same networ…
|
CWE-78
OS Command
|
CVE-2021-20138
|
2024-11-21 14:45 |
2021-12-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
200129
|
6.1 |
MEDIUM
Network
|
gryphonconnect
|
gryphon_tower_firmware
|
A reflected cross-site scripting vulnerability exists in the url parameter of the /cgi-bin/luci/site_access/ page on the Gryphon Tower router's web interface. An attacker could exploit this issue by …
|
CWE-79
Cross-site Scripting
|
CVE-2021-20137
|
2024-11-21 14:45 |
2021-12-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
200130
|
7.8 |
HIGH
Local
|
sonicwall
|
global_vpn_client
|
SonicWall Global VPN client version 4.10.6 (32-bit and 64-bit) and earlier have a DLL Search Order Hijacking vulnerability. Successful exploitation via a local attacker could result in remote code ex…
|
CWE-427
Uncontrolled Search Path Element
|
CVE-2021-20047
|
2024-11-21 14:45 |
2021-12-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|