|
190651
|
9.1 |
CRITICAL
Network
|
inhandnetworks
|
ir615_firmware
|
InHand Networks IR615 Router's Versions 2.3.0.r4724 and 2.3.0.r4870 are vulnerable to an attacker using a traceroute tool to inject commands into the device. This may allow the attacker to remotely r…
|
-
|
CVE-2021-38478
|
2024-11-21 15:17 |
2021-10-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
190652
|
5.3 |
MEDIUM
Network
|
inhandnetworks
|
ir615_firmware
|
InHand Networks IR615 Router's Versions 2.3.0.r4724 and 2.3.0.r4870 authentication process response indicates and validates the existence of a username. This may allow an attacker to enumerate differ…
|
CWE-203
Information Exposure Through Discrepancy
|
CVE-2021-38476
|
2024-11-21 15:17 |
2021-10-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
190653
|
9.8 |
CRITICAL
Network
|
inhandnetworks
|
ir615_firmware
|
InHand Networks IR615 Router's Versions 2.3.0.r4724 and 2.3.0.r4870 have has no account lockout policy configured for the login page of the product. This may allow an attacker to execute a brute-forc…
|
CWE-307
mproper Restriction of Excessive Authentication Attempts
|
CVE-2021-38474
|
2024-11-21 15:17 |
2021-10-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
190654
|
4.7 |
MEDIUM
Network
|
inhandnetworks
|
ir615_firmware
|
InHand Networks IR615 Router's Versions 2.3.0.r4724 and 2.3.0.r4870 management portal does not contain an X-FRAME-OPTIONS header, which an attacker may take advantage of by sending a link to an admin…
|
CWE-1021
Improper Restriction of Rendered UI Layers or Frames
|
CVE-2021-38472
|
2024-11-21 15:17 |
2021-10-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
190655
|
9.1 |
CRITICAL
Network
|
inhandnetworks
|
ir615_firmware
|
InHand Networks IR615 Router's Versions 2.3.0.r4724 and 2.3.0.r4870 are vulnerable to an attacker using a ping tool to inject commands into the device. This may allow the attacker to remotely run com…
|
-
|
CVE-2021-38470
|
2024-11-21 15:17 |
2021-10-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
190656
|
4.8 |
MEDIUM
Network
|
inhandnetworks
|
ir615_firmware
|
InHand Networks IR615 Router's Versions 2.3.0.r4724 and 2.3.0.r4870 are vulnerable to stored cross-scripting, which may allow an attacker to hijack sessions of users connected to the system.
|
-
|
CVE-2021-38468
|
2024-11-21 15:17 |
2021-10-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
190657
|
6.1 |
MEDIUM
Network
|
inhandnetworks
|
ir615_firmware
|
InHand Networks IR615 Router's Versions 2.3.0.r4724 and 2.3.0.r4870 do not perform sufficient input validation on client requests from the help page. This may allow an attacker to perform a reflected…
|
-
|
CVE-2021-38466
|
2024-11-21 15:17 |
2021-10-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
190658
|
7.4 |
HIGH
Network
|
inhandnetworks
|
ir615_firmware
|
InHand Networks IR615 Router's Versions 2.3.0.r4724 and 2.3.0.r4870 have inadequate encryption strength, which may allow an attacker to intercept the communication and steal sensitive information or …
|
CWE-326
Inadequate Encryption Strength
|
CVE-2021-38464
|
2024-11-21 15:17 |
2021-10-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
190659
|
9.8 |
CRITICAL
Network
|
inhandnetworks
|
ir615_firmware
|
InHand Networks IR615 Router's Versions 2.3.0.r4724 and 2.3.0.r4870 does not enforce an efficient password policy. This may allow an attacker with obtained user credentials to enumerate passwords and…
|
CWE-521
Weak Password Requirements
|
CVE-2021-38462
|
2024-11-21 15:17 |
2021-10-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
190660
|
7.8 |
HIGH
Local
|
fatek
|
winproladder
|
FATEK Automation WinProladder versions 3.30 and prior lacks proper validation of user-supplied data when parsing project files, which could result in a heap-corruption condition. An attacker could le…
|
CWE-787
Out-of-bounds Write
|
CVE-2021-38442
|
2024-11-21 15:17 |
2021-10-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|