Vulnerabilities
Vulnerable Software
Nec:  Security Vulnerabilities
Aterm WF1200CR and Aterm WG1200CR (Aterm WF1200CR firmware Ver1.1.1 and earlier, Aterm WG1200CR firmware Ver1.0.1 and earlier) allows an attacker on the same network segment to execute arbitrary OS commands via SOAP interface of UPnP.
CVSS Score
8.8
EPSS Score
0.003
Published
2019-01-09
Aterm HC100RC Ver1.0.1 and earlier allows attacker with administrator rights to execute arbitrary OS commands via import.cgi encKey parameter.
CVSS Score
7.2
EPSS Score
0.007
Published
2019-01-09
Aterm HC100RC Ver1.0.1 and earlier allows attacker with administrator rights to execute arbitrary OS commands via tools_firmware.cgi date parameter, time parameter, and offset parameter.
CVSS Score
7.2
EPSS Score
0.006
Published
2019-01-09
Buffer overflow in Aterm HC100RC Ver1.0.1 and earlier allows attacker with administrator rights to execute arbitrary code via netWizard.cgi date parameter, time parameter, and offset parameter.
CVSS Score
7.2
EPSS Score
0.02
Published
2019-01-09
Buffer overflow in Aterm HC100RC Ver1.0.1 and earlier allows attacker with administrator rights to execute arbitrary code via tools_system.cgi date parameter, time parameter, and offset parameter.
CVSS Score
7.2
EPSS Score
0.02
Published
2019-01-09
Aterm WG1200HP firmware Ver1.0.31 and earlier allows attacker with administrator rights to execute arbitrary OS commands via formSysCmd parameter.
CVSS Score
7.2
EPSS Score
0.007
Published
2019-01-09
Aterm WG1200HP firmware Ver1.0.31 and earlier allows attacker with administrator rights to execute arbitrary OS commands via sysCmd in formWsc parameter.
CVSS Score
7.2
EPSS Score
0.007
Published
2019-01-09
Aterm WG1200HP firmware Ver1.0.31 and earlier allows attacker with administrator rights to execute arbitrary OS commands via targetAPSsid parameter.
CVSS Score
7.2
EPSS Score
0.007
Published
2019-01-09
Aterm WG1200HP firmware Ver1.0.31 and earlier allows attacker with administrator rights to execute arbitrary OS commands via HTTP request and response.
CVSS Score
7.2
EPSS Score
0.007
Published
2019-01-09
Aterm W300P Ver1.0.13 and earlier allows attacker with administrator rights to execute arbitrary OS commands via HTTP request and response.
CVSS Score
7.2
EPSS Score
0.007
Published
2019-01-09


Contact Us

Shodan ® - All rights reserved