8.2

CVSS3.1

CVE-2023-37822 -

The Eufy Homebase 2 before firmware version 3.3.4.1h creates a dedicated wireless network for its ecosystem, which serves as a proxy to the end user's primary network. The WPA2-PSK generation of this dedicated network is flawed and solely based on the serial number. Due to the flawed generation pro…

πŸ“… Published: Oct. 3, 2024, midnight πŸ”„ Last Modified: Nov. 25, 2024, 10:15 p.m.

8

CVSS3.1

CVE-2024-41596 -

Buffer Overflow vulnerabilities exist in DrayTek Vigor310 devices through 4.3.2.6 (in the Vigor management UI) because of improper retrieval and handling of the CGI form parameters.

πŸ“… Published: Oct. 3, 2024, midnight πŸ”„ Last Modified: June 11, 2025, 1:40 p.m.

8

CVSS3.1

CVE-2024-41595 -

DrayTek Vigor310 devices through 4.3.2.6 allow a remote attacker to change settings or cause a denial of service via .cgi pages because of missing bounds checks on read and write operations.

πŸ“… Published: Oct. 3, 2024, midnight πŸ”„ Last Modified: April 10, 2025, 2:37 p.m.

6.1

CVSS3.1

CVE-2024-41591 -

DrayTek Vigor3910 devices through 4.3.2.6 allow unauthenticated DOM-based reflected XSS.

πŸ“… Published: Oct. 3, 2024, midnight πŸ”„ Last Modified: March 14, 2025, 4:15 p.m.

4.7

CVSS3.1

CVE-2024-41584 -

DrayTek Vigor3910 devices through 4.3.2.6 are vulnerable to reflected XSS by authenticated users, caused by missing validation of the sFormAuthStr parameter.

πŸ“… Published: Oct. 3, 2024, midnight πŸ”„ Last Modified: April 10, 2025, 6:15 p.m.

8

CVSS3.1

CVE-2024-41586 -

A stack-based Buffer Overflow vulnerability in DrayTek Vigor310 devices through 4.3.2.6 allows a remote attacker to execute arbitrary code via a long query string to the cgi-bin/ipfedr.cgi component.

πŸ“… Published: Oct. 3, 2024, midnight πŸ”„ Last Modified: April 10, 2025, 1:41 p.m.

8.8

CVSS3.1

CVE-2024-41589 -

DrayTek Vigor310 devices through 4.3.2.6 use unencrypted HTTP for authentication requests.

πŸ“… Published: Oct. 3, 2024, midnight πŸ”„ Last Modified: April 10, 2025, 1:43 p.m.

6.8

CVSS3.1

CVE-2024-41585 -

DrayTek Vigor3910 devices through 4.3.2.6 are affected by an OS command injection vulnerability that allows an attacker to leverage the recvCmd binary to escape from the emulated instance and inject arbitrary commands into the host machine.

πŸ“… Published: Oct. 3, 2024, midnight πŸ”„ Last Modified: April 10, 2025, 1:41 p.m.

6.5

CVSS3.1

CVE-2024-45870 -

Bandisoft BandiView 7.05 is vulnerable to Incorrect Access Control in sub_0x3d80fc via a crafted POC file.

πŸ“… Published: Oct. 3, 2024, midnight πŸ”„ Last Modified: April 28, 2025, 6:06 p.m.

8

CVSS3.1

CVE-2024-41588 -

The CGI endpoints v2x00.cgi and cgiwcg.cgi of DrayTek Vigor3910 devices through 4.3.2.6 are vulnerable to buffer overflows, by authenticated users, because of missing bounds checking on parameters passed through POST requests to the strncpy function.

πŸ“… Published: Oct. 3, 2024, midnight πŸ”„ Last Modified: June 11, 2025, 1:54 p.m.
Total resulsts: 349182
Page 8412 of 34,919
Β« previous page Β» next page
Filters