‼ CVE-2022-26206 ‼
📖 Read
via "National Vulnerability Database".
Totolink A830R V5.9c.4729_B20191112, A3100R V4.1.2cu.5050_B20200504, A950RG V4.1.2cu.5161_B20200903, A800R V4.1.2cu.5137_B20200730, A3000RU V5.9c.5185_B20201128, and A810R V4.1.2cu.5182_B20201026 were discovered to contain a command injection vulnerability in the function setLanguageCfg, via the langType parameter. This vulnerability allows attackers to execute arbitrary commands via a crafted request.📖 Read
via "National Vulnerability Database".
‼ CVE-2022-26214 ‼
📖 Read
via "National Vulnerability Database".
Totolink A830R V5.9c.4729_B20191112, A3100R V4.1.2cu.5050_B20200504, A950RG V4.1.2cu.5161_B20200903, A800R V4.1.2cu.5137_B20200730, A3000RU V5.9c.5185_B20201128, and A810R V4.1.2cu.5182_B20201026 were discovered to contain a command injection vulnerability in the function NTPSyncWithHost. This vulnerability allows attackers to execute arbitrary commands via the host_time parameter.📖 Read
via "National Vulnerability Database".
‼ CVE-2022-27000 ‼
📖 Read
via "National Vulnerability Database".
Arris TR3300 v1.0.13 was discovered to contain a command injection vulnerability in the time and time zone function via the h_primary_ntp_server, h_backup_ntp_server, and h_time_zone parameters. This vulnerability allows attackers to execute arbitrary commands via a crafted request.📖 Read
via "National Vulnerability Database".
‼ CVE-2022-27001 ‼
📖 Read
via "National Vulnerability Database".
Arris TR3300 v1.0.13 were discovered to contain a command injection vulnerability in the dhcp function via the hostname parameter. This vulnerability allows attackers to execute arbitrary commands via a crafted request.📖 Read
via "National Vulnerability Database".
‼ CVE-2022-26208 ‼
📖 Read
via "National Vulnerability Database".
Totolink A830R V5.9c.4729_B20191112, A3100R V4.1.2cu.5050_B20200504, A950RG V4.1.2cu.5161_B20200903, A800R V4.1.2cu.5137_B20200730, A3000RU V5.9c.5185_B20201128, and A810R V4.1.2cu.5182_B20201026 were discovered to contain a command injection vulnerability in the function setWebWlanIdx, via the webWlanIdx parameter. This vulnerability allows attackers to execute arbitrary commands via a crafted request.📖 Read
via "National Vulnerability Database".
‼ CVE-2022-26211 ‼
📖 Read
via "National Vulnerability Database".
Totolink A830R V5.9c.4729_B20191112, A3100R V4.1.2cu.5050_B20200504, A950RG V4.1.2cu.5161_B20200903, A800R V4.1.2cu.5137_B20200730, A3000RU V5.9c.5185_B20201128, and A810R V4.1.2cu.5182_B20201026 were discovered to contain a command injection vulnerability in the function CloudACMunualUpdate, via the deviceMac and deviceName parameters. This vulnerability allows attackers to execute arbitrary commands via a crafted request.📖 Read
via "National Vulnerability Database".
‼ CVE-2022-26991 ‼
📖 Read
via "National Vulnerability Database".
Arris routers SBR-AC1900P 1.0.7-B05, SBR-AC3200P 1.0.7-B05 and SBR-AC1200P 1.0.5-B05 were discovered to contain a command injection vulnerability in the ntp function via the TimeZone parameter. This vulnerability allows attackers to execute arbitrary commands via a crafted request.📖 Read
via "National Vulnerability Database".
‼ CVE-2022-26207 ‼
📖 Read
via "National Vulnerability Database".
Totolink A830R V5.9c.4729_B20191112, A3100R V4.1.2cu.5050_B20200504, A950RG V4.1.2cu.5161_B20200903, A800R V4.1.2cu.5137_B20200730, A3000RU V5.9c.5185_B20201128, and A810R V4.1.2cu.5182_B20201026 were discovered to contain a command injection vulnerability in the function setDiagnosisCfg, via the ipDoamin parameter. This vulnerability allows attackers to execute arbitrary commands via a crafted request.📖 Read
via "National Vulnerability Database".
‼ CVE-2022-26999 ‼
📖 Read
via "National Vulnerability Database".
Arris TR3300 v1.0.13 was discovered to contain a command injection vulnerability in the static ip settings function via the wan_ip_stat, wan_mask_stat, wan_gw_stat, and wan_dns1_stat parameters. This vulnerability allows attackers to execute arbitrary commands via a crafted request.📖 Read
via "National Vulnerability Database".
👍1
‼ CVE-2022-26213 ‼
📖 Read
via "National Vulnerability Database".
Totolink X5000R_Firmware v9.1.0u.6118_B20201102 was discovered to contain a command injection vulnerability in the function setNtpCfg, via the tz parameters. This vulnerability allows attackers to execute arbitrary commands via a crafted request.📖 Read
via "National Vulnerability Database".
‼ CVE-2022-26210 ‼
📖 Read
via "National Vulnerability Database".
Totolink A830R V5.9c.4729_B20191112, A3100R V4.1.2cu.5050_B20200504, A950RG V4.1.2cu.5161_B20200903, A800R V4.1.2cu.5137_B20200730, A3000RU V5.9c.5185_B20201128, and A810R V4.1.2cu.5182_B20201026 were discovered to contain a command injection vulnerability in the function setUpgradeFW, via the FileName parameter. This vulnerability allows attackers to execute arbitrary commands via a crafted request.📖 Read
via "National Vulnerability Database".
‼ CVE-2022-26993 ‼
📖 Read
via "National Vulnerability Database".
Arris routers SBR-AC1900P 1.0.7-B05, SBR-AC3200P 1.0.7-B05 and SBR-AC1200P 1.0.5-B05 were discovered to contain a command injection vulnerability in the pppoe function via the pppoeUserName, pppoePassword, and pppoe_Service parameters. This vulnerability allows attackers to execute arbitrary commands via a crafted request.📖 Read
via "National Vulnerability Database".
‼ CVE-2022-26994 ‼
📖 Read
via "National Vulnerability Database".
Arris routers SBR-AC1900P 1.0.7-B05, SBR-AC3200P 1.0.7-B05 and SBR-AC1200P 1.0.5-B05 were discovered to contain a command injection vulnerability in the pptp function via the pptpUserName and pptpPassword parameters. This vulnerability allows attackers to execute arbitrary commands via a crafted request.📖 Read
via "National Vulnerability Database".
‼ CVE-2022-26996 ‼
📖 Read
via "National Vulnerability Database".
Arris TR3300 v1.0.13 was discovered to contain a command injection vulnerability in the pppoe function via the pppoe_username, pppoe_passwd, and pppoe_servicename parameters. This vulnerability allows attackers to execute arbitrary commands via a crafted request.📖 Read
via "National Vulnerability Database".
👍1
‼ CVE-2022-26997 ‼
📖 Read
via "National Vulnerability Database".
Arris TR3300 v1.0.13 was discovered to contain a command injection vulnerability in the upnp function via the upnp_ttl parameter. This vulnerability allows attackers to execute arbitrary commands via a crafted request.📖 Read
via "National Vulnerability Database".
‼ CVE-2022-26992 ‼
📖 Read
via "National Vulnerability Database".
Arris routers SBR-AC1900P 1.0.7-B05, SBR-AC3200P 1.0.7-B05 and SBR-AC1200P 1.0.5-B05 were discovered to contain a command injection vulnerability in the ddns function via the DdnsUserName, DdnsHostName, and DdnsPassword parameters. This vulnerability allows attackers to execute arbitrary commands via a crafted request.📖 Read
via "National Vulnerability Database".
‼ CVE-2022-26998 ‼
📖 Read
via "National Vulnerability Database".
Arris TR3300 v1.0.13 was discovered to contain a command injection vulnerability in the wps setting function via the wps_enrolee_pin parameter. This vulnerability allows attackers to execute arbitrary commands via a crafted request.📖 Read
via "National Vulnerability Database".
‼ CVE-2022-26212 ‼
📖 Read
via "National Vulnerability Database".
Totolink A830R V5.9c.4729_B20191112, A3100R V4.1.2cu.5050_B20200504, A950RG V4.1.2cu.5161_B20200903, A800R V4.1.2cu.5137_B20200730, A3000RU V5.9c.5185_B20201128, and A810R V4.1.2cu.5182_B20201026 were discovered to contain a command injection vulnerability in the function setDeviceName, via the deviceMac and deviceName parameters. This vulnerability allows attackers to execute arbitrary commands via a crafted request.📖 Read
via "National Vulnerability Database".
‼ CVE-2022-27002 ‼
📖 Read
via "National Vulnerability Database".
Arris TR3300 v1.0.13 were discovered to contain a command injection vulnerability in the ddns function via the ddns_name, ddns_pwd, h_ddns?ddns_host parameters. This vulnerability allows attackers to execute arbitrary commands via a crafted request.📖 Read
via "National Vulnerability Database".
📢 US law passed forcing companies to report cyber attacks, ransomware payments 📢
📖 Read
via "ITPro".
Operators of critical infrastructure will face a subpoena for failing to report cyber incidents📖 Read
via "ITPro".
IT PRO
US law passed forcing companies to report cyber attacks, ransomware payments | IT PRO
Operators of critical infrastructure will face a subpoena for failing to report cyber incidents
📢 Ukraine given access to Clearview AI's controversial facial recognition tech 📢
📖 Read
via "ITPro".
The tech will be used to recognise Russian soldiers, tackle misinformation, and identify the deceased📖 Read
via "ITPro".
IT PRO
Ukraine given access to Clearview AI's controversial facial recognition tech | IT PRO
The tech will be used to recognise Russian soldiers, tackle misinformation, and identify the deceased