|
266471
|
7.5 |
HIGH
Network
|
dlink
|
dwr-932b_firmware
|
An issue was discovered on the D-Link DWR-932B router. A secure_mode=no line exists in /var/miniupnpd.conf.
|
CWE-254
7PK - Security Features
|
CVE-2016-10185
|
2024-11-21 11:43 |
2017-01-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266472
|
7.5 |
HIGH
Network
|
dlink
|
dwr-932b_firmware
|
An issue was discovered on the D-Link DWR-932B router. qmiweb allows file reading with ..%2f traversal.
|
CWE-22
Path Traversal
|
CVE-2016-10184
|
2024-11-21 11:43 |
2017-01-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266473
|
7.5 |
HIGH
Network
|
dlink
|
dwr-932b_firmware
|
An issue was discovered on the D-Link DWR-932B router. qmiweb allows directory listing with ../ traversal.
|
CWE-22
Path Traversal
|
CVE-2016-10183
|
2024-11-21 11:43 |
2017-01-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266474
|
9.8 |
CRITICAL
Network
|
dlink
|
dwr-932b_firmware
|
An issue was discovered on the D-Link DWR-932B router. qmiweb allows command injection with ` characters.
|
CWE-77
Command Injection
|
CVE-2016-10182
|
2024-11-21 11:43 |
2017-01-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266475
|
7.5 |
HIGH
Network
|
dlink
|
dwr-932b_firmware
|
An issue was discovered on the D-Link DWR-932B router. qmiweb provides sensitive information for CfgType=get_homeCfg requests.
|
CWE-200
Information Exposure
|
CVE-2016-10181
|
2024-11-21 11:43 |
2017-01-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266476
|
7.5 |
HIGH
Network
|
dlink
|
dwr-932b_firmware
|
An issue was discovered on the D-Link DWR-932B router. WPS PIN generation is based on srand(time(0)) seeding.
|
CWE-335
Incorrect Usage of Seeds in Pseudo-Random Number Generator (PRNG)
|
CVE-2016-10180
|
2024-11-21 11:43 |
2017-01-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266477
|
7.5 |
HIGH
Network
|
dlink
|
dwr-932b_firmware
|
An issue was discovered on the D-Link DWR-932B router. There is a hardcoded WPS PIN of 28296607.
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2016-10179
|
2024-11-21 11:43 |
2017-01-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266478
|
9.8 |
CRITICAL
Network
|
dlink
|
dwr-932b_firmware
|
An issue was discovered on the D-Link DWR-932B router. HELODBG on port 39889 (UDP) launches the "/sbin/telnetd -l /bin/sh" command.
|
CWE-254
7PK - Security Features
|
CVE-2016-10178
|
2024-11-21 11:43 |
2017-01-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266479
|
9.8 |
CRITICAL
Network
|
dlink
|
dwr-932b_firmware
|
An issue was discovered on the D-Link DWR-932B router. Undocumented TELNET and SSH services provide logins to admin with the password admin and root with the password 1234.
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2016-10177
|
2024-11-21 11:43 |
2017-01-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266480
|
9.8 |
CRITICAL
Network
|
netgear
|
wnr2000v5_firmware
|
The NETGEAR WNR2000v5 router leaks its serial number when performing a request to the /BRS_netgear_success.html URI. This serial number allows a user to obtain the administrator username and password…
|
CWE-200
Information Exposure
|
CVE-2016-10175
|
2024-11-21 11:43 |
2017-01-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|