|
196511
|
7.5 |
HIGH
Network
|
treasuredata
|
fluent_bit
|
Fluent Bit 1.6.10 has a NULL pointer dereference when an flb_malloc return value is not validated by flb_avro.c or http_server/api/v1/metrics.c.
|
CWE-476
NULL Pointer Dereference
|
CVE-2021-27186
|
2024-11-21 14:57 |
2021-02-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196512
|
9.8 |
CRITICAL
Network
|
samba-client_project
|
samba-client
|
The samba-client package before 4.0.0 for Node.js allows command injection because of the use of process.exec.
|
CWE-77
Command Injection
|
CVE-2021-27185
|
2024-11-21 14:57 |
2021-02-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196513
|
7.5 |
HIGH
Network
|
fiberhome
|
hg6245d_firmware
|
An issue was discovered on FiberHome HG6245D devices through RP2613. It is possible to crash the telnet daemon by sending a certain 0a 65 6e 61 62 6c 65 0a 02 0a 1a 0a string.
|
CWE-20
Improper Input Validation
|
CVE-2021-27179
|
2024-11-21 14:57 |
2021-02-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196514
|
7.5 |
HIGH
Network
|
fiberhome
|
hg6245d_firmware
|
An issue was discovered on FiberHome HG6245D devices through RP2613. Some passwords are stored in cleartext in nvram.
|
CWE-312
Cleartext Storage of Sensitive Information
|
CVE-2021-27178
|
2024-11-21 14:57 |
2021-02-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196515
|
9.8 |
CRITICAL
Network
|
fiberhome
|
hg6245d_firmware
|
An issue was discovered on FiberHome HG6245D devices through RP2613. It is possible to bypass authentication by sending the decoded value of the GgpoZWxwCmxpc3QKd2hvCg== string to the telnet server.
|
CWE-863
Incorrect Authorization
|
CVE-2021-27177
|
2024-11-21 14:57 |
2021-02-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196516
|
7.5 |
HIGH
Network
|
fiberhome
|
hg6245d_firmware
|
An issue was discovered on FiberHome HG6245D devices through RP2613. wifictl_5g.cfg has cleartext passwords and 0644 permissions.
|
CWE-312
Cleartext Storage of Sensitive Information
|
CVE-2021-27176
|
2024-11-21 14:57 |
2021-02-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196517
|
7.5 |
HIGH
Network
|
fiberhome
|
hg6245d_firmware
|
An issue was discovered on FiberHome HG6245D devices through RP2613. wifictl_2g.cfg has cleartext passwords and 0644 permissions.
|
CWE-312
Cleartext Storage of Sensitive Information
|
CVE-2021-27175
|
2024-11-21 14:57 |
2021-02-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196518
|
7.5 |
HIGH
Network
|
fiberhome
|
hg6245d_firmware
|
An issue was discovered on FiberHome HG6245D devices through RP2613. wifi_custom.cfg has cleartext passwords and 0644 permissions.
|
CWE-312
Cleartext Storage of Sensitive Information
|
CVE-2021-27174
|
2024-11-21 14:57 |
2021-02-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196519
|
7.5 |
HIGH
Network
|
fiberhome
|
hg6245d_firmware
|
An issue was discovered on FiberHome HG6245D devices through RP2613. There is a telnet?enable=0&key=calculated(BR0_MAC) backdoor API, without authentication, provided by the HTTP server. This will re…
|
NVD-CWE-Other
|
CVE-2021-27173
|
2024-11-21 14:57 |
2021-02-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196520
|
9.8 |
CRITICAL
Network
|
fiberhome
|
hg6245d_firmware
|
An issue was discovered on FiberHome HG6245D devices through RP2613. A hardcoded GEPON password for root is defined inside /etc/init.d/system-config.sh.
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2021-27172
|
2024-11-21 14:57 |
2021-02-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|