5.1

CVSS4.0

CVE-2018-25156 - Teradek Cube 7.3.6 Cross-Site Request Forgery Password Change

Teradek Cube 7.3.6 contains a cross-site request forgery vulnerability that allows attackers to change administrative passwords without proper request validation. Attackers can craft a malicious web page with a hidden form to submit password change requests to the device's system configuration inte…

πŸ“… Published: Dec. 24, 2025, 7:27 p.m. πŸ”„ Last Modified: March 5, 2026, 12:37 p.m.

5.1

CVSS4.0

CVE-2018-25155 - Teradek Slice 7.3.15 Cross-Site Request Forgery via Password Change

Teradek Slice 7.3.15 contains a cross-site request forgery vulnerability that allows attackers to change administrative passwords without proper request validation. Attackers can craft a malicious web page that automatically submits password change requests to the device when a logged-in user visit…

πŸ“… Published: Dec. 24, 2025, 7:27 p.m. πŸ”„ Last Modified: March 5, 2026, 12:02 p.m.

8.5

CVSS4.0

CVE-2018-25154 - GNU Barcode 0.99 Buffer Overflow in Code 93 Encoding Mechanism

GNU Barcode 0.99 contains a buffer overflow vulnerability in its code 93 encoding process that allows attackers to trigger memory corruption. Attackers can exploit boundary errors during input file processing to potentially execute arbitrary code on the affected system.

πŸ“… Published: Dec. 24, 2025, 7:27 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

0.0

CVE-2018-25153 -

This CVE ID has been rejected or withdrawn by its CVE Numbering Authority as the reported issue does not constitute a security vulnerability and represents a minor, non-exploitable memory leak.

πŸ“… Published: Dec. 24, 2025, 7:27 p.m. πŸ”„ Last Modified: Jan. 5, 2026, 12:25 p.m.

5.1

CVSS4.0

CVE-2018-25152 - Ecessa Edge EV150 10.7.4 Cross-Site Request Forgery via User Configuration

Ecessa Edge EV150 10.7.4 contains a cross-site request forgery vulnerability that allows attackers to create administrative user accounts without authentication. Attackers can craft a malicious web page with a form that submits requests to the /cgi-bin/pl_web.cgi/util_configlogin_act endpoint to ad…

πŸ“… Published: Dec. 24, 2025, 7:27 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.1

CVSS4.0

CVE-2018-25151 - Ecessa WANWorx WVR-30 < 10.7.4 Cross-Site Request Forgery via User Configuration

Ecessa WANWorx WVR-30 versions before 10.7.4 contain a cross-site request forgery vulnerability that allows attackers to perform administrative actions without request validation. Attackers can craft a malicious web page with a hidden form to create a new superuser account by tricking an authentica…

πŸ“… Published: Dec. 24, 2025, 7:27 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.1

CVSS4.0

CVE-2018-25150 - Ecessa ShieldLink SL175EHQ 10.7.4 Cross-Site Request Forgery via User Configuration

Ecessa ShieldLink SL175EHQ 10.7.4 contains a cross-site request forgery vulnerability that allows attackers to create administrative user accounts without authentication. Attackers can craft a malicious web page with a hidden form to add a superuser account by tricking a logged-in administrator int…

πŸ“… Published: Dec. 24, 2025, 7:27 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.1

CVSS4.0

CVE-2018-25149 - Microhard Systems IPn4G 1.1.0 Cross-Site Request Forgery via Web Interface

Microhard Systems IPn4G 1.1.0 contains a cross-site request forgery vulnerability that allows attackers to perform administrative actions without user consent. Attackers can craft malicious web pages to change admin passwords, add new users, and modify system settings by tricking authenticated user…

πŸ“… Published: Dec. 24, 2025, 7:27 p.m. πŸ”„ Last Modified: Jan. 26, 2026, 4:15 p.m.

8.7

CVSS4.0

CVE-2018-25148 - Microhard Systems IPn4G 1.1.0 Remote Code Execution via Admin Interface

Microhard Systems IPn4G 1.1.0 contains multiple authenticated remote code execution vulnerabilities in the admin interface that allow attackers to create crontab jobs and modify system startup scripts. Attackers can exploit hidden admin features to execute arbitrary commands with root privileges, i…

πŸ“… Published: Dec. 24, 2025, 7:27 p.m. πŸ”„ Last Modified: Jan. 21, 2026, 8 p.m.

9.3

CVSS4.0

CVE-2018-25147 - Microhard Systems IPn4G 1.1.0 Default Credentials Authentication Bypass

Microhard Systems IPn4G 1.1.0 contains hardcoded default credentials that cannot be changed through normal gateway operations. Attackers can exploit these default credentials to gain unauthorized root-level access to the device by logging in with predefined username and password combinations.

πŸ“… Published: Dec. 24, 2025, 7:27 p.m. πŸ”„ Last Modified: Jan. 26, 2026, 7:47 p.m.
Total resulsts: 349182
Page 2411 of 34,919
Β« previous page Β» next page
Filters