3.7

CVSS3.1

CVE-2026-22920 - Password Salting Weakness in SICK TDCโ€‘X401GL Device

The device's passwords have not been adequately salted, making them vulnerable to password extraction attacks.

๐Ÿ“… Published: Jan. 15, 2026, 1:09 p.m. ๐Ÿ”„ Last Modified: April 18, 2026, 6:15 a.m.

3.8

CVSS3.1

CVE-2026-22919 - Crossโ€‘Site Scripting in Sick TDCโ€‘X401GL Login Page

An attacker with administrative access may inject malicious content into the login page, potentially enabling cross-site scripting (XSS) attacks, leading to the extraction of sensitive data.

๐Ÿ“… Published: Jan. 15, 2026, 1:08 p.m. ๐Ÿ”„ Last Modified: April 18, 2026, 6:15 a.m.

4.3

CVSS3.1

CVE-2026-22918 - Missing Clickjacking Protection Allows Sensitive Data Extraction

An attacker may exploit missing protection against clickjacking by tricking users into performing unintended actions through maliciously crafted web pages, leading to the extraction of sensitive data.

๐Ÿ“… Published: Jan. 15, 2026, 1:08 p.m. ๐Ÿ”„ Last Modified: April 18, 2026, 6:15 a.m.

4.3

CVSS3.1

CVE-2026-22917 - Improper Input Handling Leading to Resource Exhaustion in SICK TDC-X401GL

Improper input handling in a system endpoint may allow attackers to overload resources, causing a denial of service.

๐Ÿ“… Published: Jan. 15, 2026, 1:07 p.m. ๐Ÿ”„ Last Modified: April 18, 2026, 4:15 p.m.

4.3

CVSS3.1

CVE-2026-22916 - Lowโ€‘Privilege Reboot/Factory Reset in SICK TDCโ€‘X401GL Controllers

An attacker with low privileges may be able to trigger critical system functions such as reboot or factory reset without proper restrictions, potentially leading to service disruption or loss of configuration.

๐Ÿ“… Published: Jan. 15, 2026, 1:07 p.m. ๐Ÿ”„ Last Modified: April 18, 2026, 4:15 p.m.

4.3

CVSS3.1

CVE-2026-22915 - Low Privilege File Disclosure via Directories in SICK TDCโ€‘X401GL

An attacker with low privileges may be able to read files from specific directories on the device, potentially exposing sensitive information.

๐Ÿ“… Published: Jan. 15, 2026, 1:06 p.m. ๐Ÿ”„ Last Modified: April 18, 2026, 6:15 a.m.

4.3

CVSS3.1

CVE-2026-22914 - Limited Permissions Permit File Write and System Manipulation

An attacker with limited permissions may still be able to write files to specific locations on the device, potentially leading to system manipulation.

๐Ÿ“… Published: Jan. 15, 2026, 1:06 p.m. ๐Ÿ”„ Last Modified: April 18, 2026, 6:15 a.m.

4.3

CVSS3.1

CVE-2026-22913 - Clientโ€‘Side Script Injection via URL Parameter on SICK TDCโ€‘X401GL

Improper handling of a URL parameter may allow attackers to execute code in a user's browser after login. This can lead to the extraction of sensitive data.

๐Ÿ“… Published: Jan. 15, 2026, 1:05 p.m. ๐Ÿ”„ Last Modified: April 18, 2026, 8 p.m.

4.3

CVSS3.1

CVE-2026-22912 - Open Redirect in SICK AG TDCโ€‘X401GL Login

Improper validation of a login parameter may allow attackers to redirect users to malicious websites after authentication. This can lead to various risk including stealing credentials from unsuspecting users.

๐Ÿ“… Published: Jan. 15, 2026, 1:03 p.m. ๐Ÿ”„ Last Modified: April 18, 2026, 6:15 a.m.

5.3

CVSS3.1

CVE-2026-22911 - Firmware Update Files Exposing Password Hashes Allow Credential Compromise

Firmware update files may expose password hashes for system accounts, which could allow a remote attacker to recover credentials and gain unauthorized access to the device.

๐Ÿ“… Published: Jan. 15, 2026, 1:02 p.m. ๐Ÿ”„ Last Modified: April 18, 2026, 6:15 a.m.
Total resulsts: 349182
Page 2120 of 34,919
ยซ previous page ยป next page
Filters