9.8

CVSS3.1

CVE-2024-54807 -

In Netgear WNR854T 1.5.2 (North America), the UPNP service is vulnerable to command injection in the function addmap_exec which parses the NewInternalClient parameter of the AddPortMapping SOAPAction into a system call without sanitation. An attacker can send a specially crafted SOAPAction request …

πŸ“… Published: March 31, 2025, midnight πŸ”„ Last Modified: April 17, 2025, 1 p.m.

9.8

CVSS3.1

CVE-2024-54803 -

Netgear WNR854T 1.5.2 (North America) is vulnerable to Command Injection. An attacker can send a specially crafted request to post.cgi, updating the nvram parameter pppoe_peer_mac and forcing a reboot. This will result in command injection.

πŸ“… Published: March 31, 2025, midnight πŸ”„ Last Modified: April 22, 2025, 6:16 p.m.

9.1

CVSS3.1

CVE-2025-22940 -

Incorrect access control in Adtran 411 ONT L80.00.0011.M2 allows unauthorized attackers to arbitrarily set the admin password.

πŸ“… Published: March 31, 2025, midnight πŸ”„ Last Modified: Aug. 18, 2025, 5:15 p.m.

9

CVSS3.1

CVE-2025-30095 -

VyOS 1.3 through 1.5 (fixed in 1.4.2) or any Debian-based system using dropbear in combination with live-build has the same Dropbear private host keys across different installations. Thus, an attacker can conduct active man-in-the-middle attacks against SSH connections if Dropbear is enabled as the…

πŸ“… Published: March 31, 2025, midnight πŸ”„ Last Modified: April 21, 2025, 6:55 p.m.

7.8

CVSS3.1

CVE-2025-21893 - keys: Fix UAF in key_put()

In the Linux kernel, the following vulnerability has been resolved: keys: Fix UAF in key_put() Once a key's reference count has been reduced to 0, the garbage collector thread may destroy it at any time and so key_put() is not allowed to touch the key after that point. The most key_put() is norm…

πŸ“… Published: March 31, 2025, midnight πŸ”„ Last Modified: May 4, 2025, 7:23 a.m.

9.8

CVSS3.1

CVE-2024-54805 -

Netgear WNR854T 1.5.2 (North America) is vulnerable to Command Injection. An attacker can send a specially crafted request to post.cgi, updating the nvram parameter get_email. After which, they can visit the send_log.cgi endpoint which uses the parameter in a system call to achieve command executio…

πŸ“… Published: March 31, 2025, midnight πŸ”„ Last Modified: April 17, 2025, 1:04 p.m.

9.8

CVSS3.1

CVE-2024-54802 -

In Netgear WNR854T 1.5.2 (North America), the UPNP service (/usr/sbin/upnp) is vulnerable to stack-based buffer overflow in the M-SEARCH Host header.

πŸ“… Published: March 31, 2025, midnight πŸ”„ Last Modified: April 22, 2025, 6:17 p.m.

9.8

CVSS3.1

CVE-2024-54809 -

Netgear Inc WNR854T 1.5.2 (North America) contains a stack-based buffer overflow vulnerability in the parse_st_header function due to use of a request header parameter in a strncpy where size is determined based on the input specified. By sending a specially crafted packet, an attacker can take con…

πŸ“… Published: March 31, 2025, midnight πŸ”„ Last Modified: April 17, 2025, 12:54 p.m.

9.8

CVSS3.1

CVE-2024-54808 -

Netgear WNR854T 1.5.2 (North America) contains a stack-based buffer overflow vulnerability in the SetDefaultConnectionService function due to an unconstrained use of sscanf. The vulnerability allows for control of the program counter and can be utilized to achieve arbitrary code execution.

πŸ“… Published: March 31, 2025, midnight πŸ”„ Last Modified: April 17, 2025, 12:55 p.m.

9.6

CVSS3.1

CVE-2025-29266 -

Unraid 7.0.0 before 7.0.1 allows remote users to access the Unraid WebGUI and web console as root without authentication if a container is running in Host networking mode with Use Tailscale enabled.

πŸ“… Published: March 31, 2025, midnight πŸ”„ Last Modified: April 1, 2025, 8:26 p.m.
Total resulsts: 343740
Page 5593 of 34,374
Β« previous page Β» next page
Filters