3 results (0.002 seconds)

CVSS: 7.2EPSS: 0%CPEs: 2EXPL: 0

14 Jun 2021 — This vulnerability allows attackers with physical access to escalate privileges on affected installations of Arlo Q Plus 1.9.0.3_278. Authentication is not required to exploit this vulnerability. The specific flaw exists within the SSH service. The device can be booted into a special operation mode where hard-coded credentials are accepted for SSH authentication. An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of root. • https://kb.arlo.com/000062592/Security-Advisory-for-Arlo-Q-Plus-SSH-Use-of-Hard-coded-Credentials-Allowing-Privilege-Escalation • CWE-798: Use of Hard-coded Credentials •

CVSS: 10.0EPSS: 0%CPEs: 10EXPL: 0

09 Jul 2019 — Arlo Basestation firmware 1.12.0.1_27940 and prior contain a hardcoded username and password combination that allows root access to the device when an onboard serial interface is connected to. Arlo Basestation firmware versión 1.12.0.1_27940 y anteriores, contienen una combinación de nombre de usuario y contraseña codificada que permite el acceso de root al dispositivo cuando se conecta una interfaz serial en tarjeta • https://kb.arlo.com/000062274/Security-Advisory-for-Networking-Misconfiguration-and-Insufficient-UART-Protection-Mechanisms • CWE-798: Use of Hard-coded Credentials •

CVSS: 9.8EPSS: 0%CPEs: 10EXPL: 0

09 Jul 2019 — Arlo Basestation firmware 1.12.0.1_27940 and prior firmware contain a networking misconfiguration that allows access to restricted network interfaces. This could allow an attacker to upload or download arbitrary files and possibly execute malicious code on the device. Arlo Basestation firmware versión 1.12.0.1_27940 y anterior, contienen una configuración inapropiada de la red que permite el acceso a las interfaces de red restringidas. Esto podría permitir a un atacante cargar o descargar archivos arbitrari... • https://kb.arlo.com/000062274/Security-Advisory-for-Networking-Misconfiguration-and-Insufficient-UART-Protection-Mechanisms • CWE-16: Configuration •