|
246661
|
7.3 |
HIGH
Network
|
eltex
|
esp-200_firmware
|
An attacker without authentication can login with default credentials for privileged users in Eltex ESP-200 firmware version 1.2.0.
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2018-15360
|
2024-11-21 12:50 |
2018-08-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246662
|
8.8 |
HIGH
Network
|
eltex
|
esp-200_firmware
|
An authenticated attacker with low privileges can use insecure sudo configuration to expand attack surface in Eltex ESP-200 firmware version 1.2.0.
|
NVD-CWE-noinfo
|
CVE-2018-15359
|
2024-11-21 12:50 |
2018-08-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246663
|
8.8 |
HIGH
Network
|
eltex
|
esp-200_firmware
|
An authenticated attacker with low privileges can activate high privileged user and use it to expand attack surface in Eltex ESP-200 firmware version 1.2.0.
|
CWE-20
Improper Input Validation
|
CVE-2018-15358
|
2024-11-21 12:50 |
2018-08-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246664
|
6.5 |
MEDIUM
Network
|
eltex
|
esp-200_firmware
|
An authenticated attacker with low privileges can extract password hash information for all users in Eltex ESP-200 firmware version 1.2.0.
|
CWE-200
Information Exposure
|
CVE-2018-15357
|
2024-11-21 12:50 |
2018-08-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246665
|
8.8 |
HIGH
Network
|
eltex
|
esp-200_firmware
|
An authenticated attacker can execute arbitrary code using command ejection in Eltex ESP-200 firmware version 1.2.0.
|
CWE-77
Command Injection
|
CVE-2018-15356
|
2024-11-21 12:50 |
2018-08-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246666
|
5.9 |
MEDIUM
Network
|
kraftway
|
24f2xg_router_firmware
|
Usage of SSLv2 and SSLv3 leads to transmitted data decryption in Kraftway 24F2XG Router firmware 3.5.30.1118.
|
CWE-327
Use of a Broken or Risky Cryptographic Algorithm
|
CVE-2018-15355
|
2024-11-21 12:50 |
2018-08-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246667
|
7.5 |
HIGH
Network
|
kraftway
|
24f2xg_router_firmware
|
A Buffer Overflow exploited through web interface by remote attacker can cause denial of service in Kraftway 24F2XG Router firmware 3.5.30.1118.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2018-15354
|
2024-11-21 12:50 |
2018-08-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246668
|
9.8 |
CRITICAL
Network
|
kraftway
|
24f2xg_router_firmware
|
A Buffer Overflow exploited through web interface by remote attacker can cause remote code execution in Kraftway 24F2XG Router firmware 3.5.30.1118.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2018-15353
|
2024-11-21 12:50 |
2018-08-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246669
|
6.5 |
MEDIUM
Network
|
kraftway
|
24f2xg_router_firmware
|
An attacker with low privileges can cause denial of service in Kraftway 24F2XG Router firmware version 3.5.30.1118.
|
NVD-CWE-noinfo
|
CVE-2018-15352
|
2024-11-21 12:50 |
2018-08-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246670
|
6.5 |
MEDIUM
Network
|
kraftway
|
24f2xg_router_firmware
|
Denial of service via crafting malicious link and sending it to a privileged user can cause Denial of Service in Kraftway 24F2XG Router firmware version 3.5.30.1118.
|
CWE-59
Link Following
|
CVE-2018-15351
|
2024-11-21 12:50 |
2018-08-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|