‼ CVE-2021-46229 ‼
📖 Read
via "National Vulnerability Database".
D-Link device DI-7200GV2.E1 v21.04.09E1 was discovered to contain a command injection vulnerability in the function usb_paswd.asp. This vulnerability allows attackers to execute arbitrary commands via the name parameter.📖 Read
via "National Vulnerability Database".
‼ CVE-2021-44880 ‼
📖 Read
via "National Vulnerability Database".
D-Link devices DIR_878 DIR_878_FW1.30B08_Hotfix_02 and DIR_882 DIR_882_FW1.30B06_Hotfix_02 were discovered to contain a command injection vulnerability in the system function. This vulnerability allows attackers to execute arbitrary commands via a crafted HNAP1 POST request.📖 Read
via "National Vulnerability Database".
‼ CVE-2022-24146 ‼
📖 Read
via "National Vulnerability Database".
Tenda AX3 v16.03.12.10_CN was discovered to contain a stack overflow in the function formSetQosBand. This vulnerability allows attackers to cause a Denial of Service (DoS) via the list parameter.📖 Read
via "National Vulnerability Database".
‼ CVE-2022-24167 ‼
📖 Read
via "National Vulnerability Database".
Tenda routers G1 and G3 v15.11.0.17(9502)_CN were discovered to contain a command injection vulnerability in the function formSetDMZ. This vulnerability allows attackers to execute arbitrary commands via the dmzHost1 parameter.📖 Read
via "National Vulnerability Database".
‼ CVE-2022-24168 ‼
📖 Read
via "National Vulnerability Database".
Tenda routers G1 and G3 v15.11.0.17(9502)_CN were discovered to contain a command injection vulnerability in the function formSetIpGroup. This vulnerability allows attackers to execute arbitrary commands via the IPGroupStartIP and IPGroupEndIP parameters.📖 Read
via "National Vulnerability Database".
‼ CVE-2021-46226 ‼
📖 Read
via "National Vulnerability Database".
D-Link device DI-7200GV2.E1 v21.04.09E1 was discovered to contain a command injection vulnerability in the function wget_test.asp. This vulnerability allows attackers to execute arbitrary commands via the url parameter.📖 Read
via "National Vulnerability Database".
‼ CVE-2021-44246 ‼
📖 Read
via "National Vulnerability Database".
Totolink devices A3100R v4.1.2cu.5050_B20200504, A830R v5.9c.4729_B20191112, and A720R v4.1.5cu.470_B20200911 were discovered to contain a stack overflow in the function setNoticeCfg. This vulnerability allows attackers to cause a Denial of Service (DoS) via the IpTo parameter.📖 Read
via "National Vulnerability Database".
‼ CVE-2021-45734 ‼
📖 Read
via "National Vulnerability Database".
TOTOLINK X5000R v9.1.0u.6118_B20201102 was discovered to contain a stack overflow in the function setUrlFilterRules. This vulnerability allows attackers to cause a Denial of Service (DoS) via the url parameter.📖 Read
via "National Vulnerability Database".
‼ CVE-2021-44881 ‼
📖 Read
via "National Vulnerability Database".
D-Link device DIR_882 DIR_882_FW1.30B06_Hotfix_02 was discovered to contain a command injection vulnerability in the twsystem function. This vulnerability allows attackers to execute arbitrary commands via a crafted HNAP1 POST request.📖 Read
via "National Vulnerability Database".
‼ CVE-2021-46231 ‼
📖 Read
via "National Vulnerability Database".
D-Link device DI-7200GV2.E1 v21.04.09E1 was discovered to contain a command injection vulnerability in the function urlrd_opt.asp. This vulnerability allows attackers to execute arbitrary commands via the url_en parameter.📖 Read
via "National Vulnerability Database".
‼ CVE-2022-24151 ‼
📖 Read
via "National Vulnerability Database".
Tenda AX3 v16.03.12.10_CN was discovered to contain a stack overflow in the function fromSetWifiGusetBasic. This vulnerability allows attackers to cause a Denial of Service (DoS) via the shareSpeed parameter.📖 Read
via "National Vulnerability Database".
‼ CVE-2022-24171 ‼
📖 Read
via "National Vulnerability Database".
Tenda routers G1 and G3 v15.11.0.17(9502)_CN were discovered to contain a command injection vulnerability in the function formSetPppoeServer. This vulnerability allows attackers to execute arbitrary commands via the pppoeServerIP, pppoeServerStartIP, and pppoeServerEndIP parameters.📖 Read
via "National Vulnerability Database".
‼ CVE-2022-24160 ‼
📖 Read
via "National Vulnerability Database".
Tenda AX3 v16.03.12.10_CN was discovered to contain a stack overflow in the function formSetDeviceName. This vulnerability allows attackers to cause a Denial of Service (DoS) via the devName parameter.📖 Read
via "National Vulnerability Database".
‼ CVE-2021-45736 ‼
📖 Read
via "National Vulnerability Database".
TOTOLINK X5000R v9.1.0u.6118_B20201102 was discovered to contain a stack overflow in the function setL2tpServerCfg. This vulnerability allows attackers to cause a Denial of Service (DoS) via the eip, sip, server parameters.📖 Read
via "National Vulnerability Database".
‼ CVE-2022-24159 ‼
📖 Read
via "National Vulnerability Database".
Tenda AX3 v16.03.12.10_CN was discovered to contain a stack overflow in the function formSetPPTPServer. This vulnerability allows attackers to cause a Denial of Service (DoS) via the startIp and endIp parameters.📖 Read
via "National Vulnerability Database".
‼ CVE-2022-24165 ‼
📖 Read
via "National Vulnerability Database".
Tenda routers G1 and G3 v15.11.0.17(9502)_CN were discovered to contain a command injection vulnerability in the function formSetQvlanList. This vulnerability allows attackers to execute arbitrary commands via the qvlanIP parameter.📖 Read
via "National Vulnerability Database".
‼ CVE-2021-45992 ‼
📖 Read
via "National Vulnerability Database".
Tenda routers G1 and G3 v15.11.0.17(9502)_CN were discovered to contain a stack overflow in the function formSetQvlanList. This vulnerability allows attackers to cause a Denial of Service (DoS) via the qvlanName parameter.📖 Read
via "National Vulnerability Database".
‼ CVE-2022-24155 ‼
📖 Read
via "National Vulnerability Database".
Tenda AX3 v16.03.12.10_CN was discovered to contain a heap overflow in the function setSchedWifi. This vulnerability allows attackers to cause a Denial of Service (DoS) via the schedStartTime and schedEndTime parameters.📖 Read
via "National Vulnerability Database".
‼ CVE-2021-45986 ‼
📖 Read
via "National Vulnerability Database".
Tenda routers G1 and G3 v15.11.0.17(9502)_CN were discovered to contain a command injection vulnerability in the function formSetUSBShareInfo. This vulnerability allows attackers to execute arbitrary commands via the usbOrdinaryUserName parameter.📖 Read
via "National Vulnerability Database".
‼ CVE-2021-45991 ‼
📖 Read
via "National Vulnerability Database".
Tenda routers G1 and G3 v15.11.0.17(9502)_CN were discovered to contain a stack overflow in the function formAddVpnUsers. This vulnerability allows attackers to cause a Denial of Service (DoS) via the vpnUsers parameter.📖 Read
via "National Vulnerability Database".
‼ CVE-2021-46228 ‼
📖 Read
via "National Vulnerability Database".
D-Link device DI-7200GV2.E1 v21.04.09E1 was discovered to contain a command injection vulnerability in the function httpd_debug.asp. This vulnerability allows attackers to execute arbitrary commands via the time parameter.📖 Read
via "National Vulnerability Database".