|
196661
|
4.9 |
MEDIUM
Network
|
ibm
|
security_verify_information_queue
|
IBM Security Verify Information Queue 1.0.6 and 1.0.7 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 196184.
|
-
|
CVE-2021-20406
|
2024-11-21 14:46 |
2021-02-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196662
|
9.1 |
CRITICAL
Network
|
elecom
|
file_manager
|
Directory traversal vulnerability in ELECOM File Manager all versions allows remote attackers to create an arbitrary file or overwrite an existing file in a directory which can be accessed with the a…
|
CWE-22
Path Traversal
|
CVE-2021-20651
|
2024-11-21 14:46 |
2021-02-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196663
|
6.5 |
MEDIUM
Network
|
elecom
|
ncc-ewf100rmwh2_firmware
|
Cross-site request forgery (CSRF) vulnerability in ELECOM NCC-EWF100RMWH2 allows remote attackers to hijack the authentication of administrators and execute an arbitrary request via unspecified vecto…
|
CWE-352
Origin Validation Error
|
CVE-2021-20650
|
2024-11-21 14:46 |
2021-02-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196664
|
4.8 |
MEDIUM
Network
|
elecom
|
wrc-300febk-s_firmware
|
ELECOM WRC-300FEBK-S contains an improper certificate validation vulnerability. Via a man-in-the-middle attack, an attacker may alter the communication response. As a result, an arbitrary OS command …
|
CWE-295
Improper Certificate Validation
|
CVE-2021-20649
|
2024-11-21 14:46 |
2021-02-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196665
|
6.8 |
MEDIUM
Adjacent
|
elecom
|
wrc-300febk-s_firmware
|
ELECOM WRC-300FEBK-S allows an attacker with administrator rights to execute arbitrary OS commands via unspecified vectors.
|
CWE-78
OS Command
|
CVE-2021-20648
|
2024-11-21 14:46 |
2021-02-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196666
|
6.5 |
MEDIUM
Network
|
elecom
|
wrc-300febk-s_firmware
|
Cross-site request forgery (CSRF) vulnerability in ELECOM WRC-300FEBK-S allows remote attackers to hijack the authentication of administrators and execute an arbitrary request via unspecified vector.…
|
CWE-352
Origin Validation Error
|
CVE-2021-20647
|
2024-11-21 14:46 |
2021-02-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196667
|
6.5 |
MEDIUM
Network
|
elecom
|
wrc-300febk-a_firmware
|
Cross-site request forgery (CSRF) vulnerability in ELECOM WRC-300FEBK-A allows remote attackers to hijack the authentication of administrators and execute an arbitrary request via unspecified vector.…
|
CWE-352
Origin Validation Error
|
CVE-2021-20646
|
2024-11-21 14:46 |
2021-02-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196668
|
5.4 |
MEDIUM
Network
|
elecom
|
wrc-300febk-a_firmware
|
Cross-site scripting vulnerability in ELECOM WRC-300FEBK-A allows remote authenticated attackers to inject arbitrary script via unspecified vectors.
|
CWE-79
Cross-site Scripting
|
CVE-2021-20645
|
2024-11-21 14:46 |
2021-02-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196669
|
6.1 |
MEDIUM
Network
|
elecom
|
wrc-1467ghbk-a_firmware
|
ELECOM WRC-1467GHBK-A allows arbitrary scripts to be executed on the user's web browser by displaying a specially crafted SSID on the web setup page.
|
CWE-74
Injection
|
CVE-2021-20644
|
2024-11-21 14:46 |
2021-02-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196670
|
7.5 |
HIGH
Network
|
elecom
|
ld-ps\/u1_firmware
|
Improper access control vulnerability in ELECOM LD-PS/U1 allows remote attackers to change the administrative password of the affected device by processing a specially crafted request.
|
NVD-CWE-Other
|
CVE-2021-20643
|
2024-11-21 14:46 |
2021-02-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|