|
190641
|
9.8 |
CRITICAL
Network
|
auvesy
|
versiondog
|
The data of a network capture of the initial handshake phase can be used to authenticate at a SYSDBA level. If a specific .exe is not restarted often, it is possible to access the needed handshake pa…
|
-
|
CVE-2021-38459
|
2024-11-21 15:17 |
2021-10-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
190642
|
9.8 |
CRITICAL
Network
|
auvesy
|
versiondog
|
The server permits communication without any authentication procedure, allowing the attacker to initiate a session with the server without providing any form of authentication.
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2021-38457
|
2024-11-21 15:17 |
2021-10-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
190643
|
6.5 |
MEDIUM
Network
|
auvesy
|
versiondog
|
The affected product’s OS Service does not verify any given parameter. A user can supply any type of parameter that will be passed to inner calls without checking the type of the parameter or the val…
|
-
|
CVE-2021-38455
|
2024-11-21 15:17 |
2021-10-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
190644
|
9.1 |
CRITICAL
Network
|
auvesy
|
versiondog
|
Some API functions allow interaction with the registry, which includes reading values as well as data modification.
|
-
|
CVE-2021-38453
|
2024-11-21 15:17 |
2021-10-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
190645
|
5.7 |
MEDIUM
Network
|
auvesy
|
versiondog
|
The affected product’s proprietary protocol CSC allows for calling numerous function codes. In order to call those function codes, the user must supply parameters. There is no sanitation on the value…
|
-
|
CVE-2021-38451
|
2024-11-21 15:17 |
2021-10-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
190646
|
9.8 |
CRITICAL
Network
|
auvesy
|
versiondog
|
Some API functions permit by-design writing or copying data into a given buffer. Since the client controls these parameters, an attacker could rewrite the memory in any location of the affected produ…
|
-
|
CVE-2021-38449
|
2024-11-21 15:17 |
2021-10-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
190647
|
8.5 |
HIGH
Network
|
inhandnetworks
|
ir615_firmware
|
InHand Networks IR615 Router's Versions 2.3.0.r4724 and 2.3.0.r4870 cloud portal allows for self-registration of the affected product without any requirements to create an account, which may allow an…
|
CWE-862
Missing Authorization
|
CVE-2021-38486
|
2024-11-21 15:17 |
2021-10-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
190648
|
7.2 |
HIGH
Network
|
inhandnetworks
|
ir615_firmware
|
InHand Networks IR615 Router's Versions 2.3.0.r4724 and 2.3.0.r4870 do not have a filter or signature check to detect or prevent an upload of malicious files to the server, which may allow an attacke…
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2021-38484
|
2024-11-21 15:17 |
2021-10-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
190649
|
4.8 |
MEDIUM
Network
|
inhandnetworks
|
ir615_firmware
|
InHand Networks IR615 Router's Versions 2.3.0.r4724 and 2.3.0.r4870 website used to control the router is vulnerable to stored cross-site scripting, which may allow an attacker to hijack sessions of …
|
CWE-79
Cross-site Scripting
|
CVE-2021-38482
|
2024-11-21 15:17 |
2021-10-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
190650
|
8.8 |
HIGH
Network
|
inhandnetworks
|
ir615_firmware
|
InHand Networks IR615 Router's Versions 2.3.0.r4724 and 2.3.0.r4870 are vulnerable to cross-site request forgery when unauthorized commands are submitted from a user the web application trusts. This …
|
-
|
CVE-2021-38480
|
2024-11-21 15:17 |
2021-10-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|