Quadron-Research-Lab/Hardware-IoT

Quadron-Research-Lab/Hardware-IoT

Releases0
Stars4

CVE History

CVEPublishedCVSS v3CVSS v2
6.5 MEDIUM4 MEDIUM

D-LINK DIR-825 AC1200 R2 is vulnerable to Directory Traversal. An attacker could use the "../../../../" setting of the FTP server folder to set the router's root folder for FTP access. This allows you to access the entire router file system via the FTP server.

7.2 HIGH6.5 MEDIUM

TP-LINK TL-WR840N(ES)_V6.20 was discovered to contain a buffer overflow via the DNSServers parameter.

7.2 HIGH6.5 MEDIUM

TP-LINK TL-WR840N(ES)_V6.20 was discovered to contain a buffer overflow via the minAddress parameter.

7.2 HIGH6.5 MEDIUM

TP-LINK TL-WR840N(ES)_V6.20 was discovered to contain a buffer overflow via the httpRemotePort parameter.

7.2 HIGH6.5 MEDIUM

TP-LINK TL-WR840N(ES)_V6.20 was discovered to contain a buffer overflow via the X_TP_ClonedMACAddress parameter.

9.8 CRITICAL7.5 HIGH

A Command injection vulnerability exists in Tenda AC10U AC1200 Smart Dual-band Wireless Router AC10U V1.0 Firmware V15.03.06.49_multi via the setUsbUnload functionality. The vulnerability is caused because the client controlled "deviceName" value is passed directly to the "doSystemCmd" function.