Vulnerabilities
Vulnerable Software
Security Vulnerabilities - CVEs Published In 2024
The Waybox Enel X web management application contains a PHP-type juggling vulnerability that may allow a brute force process and under certain conditions bypass authentication.
CVSS Score
4.2
EPSS Score
0.003
Published
2024-11-05
Under certain conditions, through a request directed to the Waybox Enel X web management application, information like Waybox OS version or service configuration details could be obtained.
CVSS Score
4.3
EPSS Score
0.002
Published
2024-11-05
Waybox Enel X web management API authentication could be bypassed and provide administrator’s privileges over the Waybox system.
CVSS Score
8.8
EPSS Score
0.003
Published
2024-11-05
Waybox Enel X web management application could execute arbitrary requests on the internal database via /admin/versions.php.
CVSS Score
9.6
EPSS Score
0.003
Published
2024-11-05
Waybox Enel X web management application could execute arbitrary requests on the internal database via /admin/dbstore.php.
CVSS Score
9.6
EPSS Score
0.003
Published
2024-11-05
Netgear R8500 v1.0.2.160, XR300 v1.0.3.78, R7000P v1.3.3.154, and R6400 v2 1.0.4.128 were discovered to contain a command injection vulnerability in the component wlg_adv.cgi via the apmode_gateway parameter. This vulnerability allows attackers to execute arbitrary OS commands via a crafted request.
CVSS Score
8.0
EPSS Score
0.01
Published
2024-11-05
Netgear XR300 v1.0.3.78, R7000P v1.3.3.154, and R6400 v2 1.0.4.128 was discovered to contain a stack overflow via the pppoe_localip parameter at pppoe2.cgi. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.
CVSS Score
5.7
EPSS Score
0.003
Published
2024-11-05
Netgear XR300 v1.0.3.78, R7000P v1.3.3.154, and R6400 v2 1.0.4.128 was discovered to contain a stack overflow via the pppoe_localip parameter at wizpppoe.cgi. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.
CVSS Score
5.7
EPSS Score
0.003
Published
2024-11-05
Netgear XR300 v1.0.3.78, R7000P v1.3.3.154, and R6400 v2 1.0.4.128 was discovered to contain a stack overflow via the pppoe_localip parameter at geniepppoe.cgi. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.
CVSS Score
5.7
EPSS Score
0.003
Published
2024-11-05
Netgear XR300 v1.0.3.78, R7000P v1.3.3.154, and R6400 v2 1.0.4.128 was discovered to contain a stack overflow via the pppoe_localip parameter at bsw_pppoe.cgi. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.
CVSS Score
5.7
EPSS Score
0.003
Published
2024-11-05


Contact Us

Shodan ® - All rights reserved