|
267131
|
9.8 |
CRITICAL
Network
|
dlink
|
dwr-932b_firmware
|
An issue was discovered on the D-Link DWR-932B router. qmiweb allows command injection with ` characters.
|
CWE-77
Command Injection
|
CVE-2016-10182
|
2024-11-21 11:43 |
2017-01-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267132
|
7.5 |
HIGH
Network
|
dlink
|
dwr-932b_firmware
|
An issue was discovered on the D-Link DWR-932B router. qmiweb provides sensitive information for CfgType=get_homeCfg requests.
|
CWE-200
Information Exposure
|
CVE-2016-10181
|
2024-11-21 11:43 |
2017-01-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267133
|
7.5 |
HIGH
Network
|
dlink
|
dwr-932b_firmware
|
An issue was discovered on the D-Link DWR-932B router. WPS PIN generation is based on srand(time(0)) seeding.
|
CWE-335
Incorrect Usage of Seeds in Pseudo-Random Number Generator (PRNG)
|
CVE-2016-10180
|
2024-11-21 11:43 |
2017-01-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267134
|
7.5 |
HIGH
Network
|
dlink
|
dwr-932b_firmware
|
An issue was discovered on the D-Link DWR-932B router. There is a hardcoded WPS PIN of 28296607.
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2016-10179
|
2024-11-21 11:43 |
2017-01-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267135
|
9.8 |
CRITICAL
Network
|
dlink
|
dwr-932b_firmware
|
An issue was discovered on the D-Link DWR-932B router. HELODBG on port 39889 (UDP) launches the "/sbin/telnetd -l /bin/sh" command.
|
CWE-254
7PK - Security Features
|
CVE-2016-10178
|
2024-11-21 11:43 |
2017-01-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267136
|
9.8 |
CRITICAL
Network
|
dlink
|
dwr-932b_firmware
|
An issue was discovered on the D-Link DWR-932B router. Undocumented TELNET and SSH services provide logins to admin with the password admin and root with the password 1234.
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2016-10177
|
2024-11-21 11:43 |
2017-01-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267137
|
9.8 |
CRITICAL
Network
|
netgear
|
wnr2000v5_firmware
|
The NETGEAR WNR2000v5 router leaks its serial number when performing a request to the /BRS_netgear_success.html URI. This serial number allows a user to obtain the administrator username and password…
|
CWE-200
Information Exposure
|
CVE-2016-10175
|
2024-11-21 11:43 |
2017-01-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267138
|
9.8 |
CRITICAL
Network
|
netgear
|
wnr2000v5_firmware
|
The NETGEAR WNR2000v5 router allows an administrator to perform sensitive actions by invoking the apply.cgi URL on the web server of the device. This special URL is handled by the embedded web server…
|
CWE-20
Improper Input Validation
|
CVE-2016-10176
|
2024-11-21 11:43 |
2017-01-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267139
|
7.5 |
HIGH
Network
|
squid-cache
|
squid
|
Incorrect HTTP Request header comparison in Squid HTTP Proxy 3.5.0.1 through 3.5.22, and 4.0.1 through 4.0.16 results in Collapsed Forwarding feature mistakenly identifying some private responses as …
|
CWE-697
Incorrect Comparison
|
CVE-2016-10003
|
2024-11-21 11:43 |
2017-01-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267140
|
7.5 |
HIGH
Network
|
debian squid-cache
|
debian_linux squid
|
Incorrect processing of responses to If-None-Modified HTTP conditional requests in Squid HTTP Proxy 3.1.10 through 3.1.23, 3.2.0.3 through 3.5.22, and 4.0.1 through 4.0.16 leads to client-specific Co…
|
CWE-200
Information Exposure
|
CVE-2016-10002
|
2024-11-21 11:43 |
2017-01-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|