Security Vulnerabilities
- CVEs Published In May 2024
Cross Site Scripting vulnerability in TOTOLINK X2000R before v1.0.0-B20231213.1013 allows a remote attacker to execute arbitrary code via the Guest Access Control parameter in the Wireless Page.
QuickJS commit 3b45d15 was discovered to contain an Assertion Failure via JS_FreeRuntime(JSRuntime *) at quickjs.c.
NULL pointer access vulnerability in the clock module
Impact: Successful exploitation of this vulnerability will affect availability.
Cracking vulnerability in the OS security module
Impact: Successful exploitation of this vulnerability will affect availability.
Privilege escalation vulnerability in the account module
Impact: Successful exploitation of this vulnerability will affect availability.
Race condition vulnerability in the binder driver module
Impact: Successful exploitation of this vulnerability will affect availability.
Out-of-bounds access vulnerability in the memory module
Impact: Successful exploitation of this vulnerability will affect availability.
Denial of service (DoS) vulnerability in the AMS module
Impact: Successful exploitation of this vulnerability will affect availability.
Permission verification vulnerability in the wpa_supplicant module
Impact: Successful exploitation of this vulnerability will affect availability.
Insufficient verification vulnerability in the baseband module
Impact: Successful exploitation of this vulnerability will affect availability.