7.3

CVSS3.1

CVE-2025-44647 -

In TRENDnet TEW-WLC100P 2.03b03, the i_dont_care_about_security_and_use_aggressive_mode_psk option is enabled in the strongSwan configuration file, so that IKE Responders are allowed to use IKEv1 Aggressive Mode with Pre-Shared Keys to conduct offline attacks on the openly transmitted hash of the Pโ€ฆ

๐Ÿ“… Published: July 21, 2025, midnight ๐Ÿ”„ Last Modified: Aug. 7, 2025, 5:55 p.m.

7.5

CVSS3.1

CVE-2025-44652 -

In Netgear RAX30 V1.0.10.94_3, the USERLIMIT_GLOBAL option is set to 0 in multiple bftpd-related configuration files. This can cause DoS attacks when unlimited users are connected.

๐Ÿ“… Published: July 21, 2025, midnight ๐Ÿ”„ Last Modified: Jan. 2, 2026, 9:04 p.m.

6.5

CVSS3.1

CVE-2025-7777 - Mirror-registry: host header injection in mirror-registry

The mirror-registry doesn't properly sanitize the host header HTTP header in HTTP request received, allowing an attacker to perform malicious redirects to attacker-controlled domains or phishing campaigns.

๐Ÿ“… Published: July 21, 2025, midnight ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

9.8

CVSS3.1

CVE-2025-44655 -

In TOTOLink A7100RU V7.4, A950RG V5.9, and T10 V5.9, the chroot_local_user option is enabled in the vsftpd.conf. This could lead to unauthorized access to system files, privilege escalation, or use of the compromised server as a pivot point for internal network attacks.

๐Ÿ“… Published: July 21, 2025, midnight ๐Ÿ”„ Last Modified: Aug. 7, 2025, 5:58 p.m.

9.8

CVSS3.1

CVE-2025-36846 -

An issue was discovered in Eveo URVE Web Manager 27.02.2025. The application exposes a /_internal/pc/vpro.php localhost endpoint to unauthenticated users that is vulnerable to OS Command Injection. The endpoint takes an input parameter that is passed directly into the shell_exec() function of PHP. โ€ฆ

๐Ÿ“… Published: July 21, 2025, midnight ๐Ÿ”„ Last Modified: Sept. 12, 2025, 5:58 p.m.

5.3

CVSS3.1

CVE-2025-46118 -

An issue was discovered in CommScope Ruckus Unleashed prior to 200.15.6.212.14 and 200.17.7.0.139 and in Ruckus ZoneDirector prior to 10.5.1.0.279, where hard-coded credentials for the ftpuser account provide FTP access to the controller, enabling a remote attacker to upload or retrieve arbitrary fโ€ฆ

๐Ÿ“… Published: July 21, 2025, midnight ๐Ÿ”„ Last Modified: Aug. 5, 2025, 5:18 p.m.

7.5

CVSS3.1

CVE-2025-44653 -

In H3C GR2200 MiniGR1A0V100R016, the USERLIMIT_GLOBAL option is set to 0 in the /etc/bftpd.conf. This can cause DoS attacks when unlimited users are connected.

๐Ÿ“… Published: July 21, 2025, midnight ๐Ÿ”„ Last Modified: Aug. 7, 2025, 2:15 p.m.

3.9

CVSS3.1

CVE-2025-44657 -

In Linksys EA6350 V2.1.2, the chroot_local_user option is enabled in the dynamically generated vsftpd configuration file. This could lead to unauthorized access to system files, privilege escalation, or use of the compromised server as a pivot point for internal network attacks.

๐Ÿ“… Published: July 21, 2025, midnight ๐Ÿ”„ Last Modified: Aug. 7, 2025, 5:58 p.m.

9.1

CVSS3.1

CVE-2025-46122 -

An issue was discovered in CommScope Ruckus Unleashed prior to 200.15.6.212.14 and 200.17.7.0.139, where the authenticated diagnostics API endpoint `/admin/_cmdstat.jsp` passes attacker-controlled input to the shell without adequate validation, enabling a remote attacker to specify a target by MAC โ€ฆ

๐Ÿ“… Published: July 21, 2025, midnight ๐Ÿ”„ Last Modified: Aug. 5, 2025, 5:18 p.m.

9.8

CVSS3.1

CVE-2025-44658 -

In Netgear RAX30 V1.0.10.94, a PHP-FPM misconfiguration vulnerability is caused by not following the specification to only limit FPM to .php extensions. An attacker may exploit this by uploading malicious scripts disguised with alternate extensions and tricking the web server into executing them asโ€ฆ

๐Ÿ“… Published: July 21, 2025, midnight ๐Ÿ”„ Last Modified: Aug. 7, 2025, 5:57 p.m.
Total resulsts: 349182
Page 4579 of 34,919
ยซ previous page ยป next page
Filters