CVE-2022-30543
https://notcve.org/view.php?id=CVE-2022-30543
09 Nov 2022 — A leftover debug code vulnerability exists in the console infct functionality of InHand Networks InRouter302 V3.5.45. A specially-crafted series of network requests can lead to execution of privileged operations. An attacker can send a sequence of requests to trigger this vulnerability. Existe una vulnerabilidad de código de depuración sobrante en la funcionalidad de infección de la consola de InHand Networks InRouter302 V3.5.45. Una serie de solicitudes de red especialmente manipuladas pueden conducir a la... • https://inhandnetworks.com/upload/attachment/202210/25/InHand-PSA-2022-02.pdf • CWE-489: Active Debug Code •
CVE-2022-29888
https://notcve.org/view.php?id=CVE-2022-29888
09 Nov 2022 — A leftover debug code vulnerability exists in the httpd port 4444 upload.cgi functionality of InHand Networks InRouter302 V3.5.45. A specially-crafted HTTP request can lead to arbitrary file deletion. An attacker can send an HTTP request to trigger this vulnerability. Existe una vulnerabilidad de código de depuración sobrante en la funcionalidad upload.cgi del puerto httpd 4444 de InHand Networks InRouter302 V3.5.45. Una solicitud HTTP especialmente manipulada puede provocar la eliminación arbitraria de un ... • https://inhandnetworks.com/upload/attachment/202210/25/InHand-PSA-2022-02.pdf • CWE-489: Active Debug Code •
CVE-2022-29481
https://notcve.org/view.php?id=CVE-2022-29481
09 Nov 2022 — A leftover debug code vulnerability exists in the console nvram functionality of InHand Networks InRouter302 V3.5.45. A specially-crafted series of network requests can lead to disabling security features. An attacker can send a sequence of requests to trigger this vulnerability. Existe una vulnerabilidad de código de depuración sobrante en la funcionalidad nvram de la consola de InHand Networks InRouter302 V3.5.45. Una serie de solicitudes de red especialmente manipuladas pueden provocar la desactivación d... • https://inhandnetworks.com/upload/attachment/202210/25/InHand-PSA-2022-02.pdf • CWE-489: Active Debug Code •
CVE-2022-28689
https://notcve.org/view.php?id=CVE-2022-28689
09 Nov 2022 — A leftover debug code vulnerability exists in the console support functionality of InHand Networks InRouter302 V3.5.45. A specially-crafted network request can lead to arbitrary command execution. An attacker can send a sequence of requests to trigger this vulnerability. Existe una vulnerabilidad de código de depuración sobrante en la funcionalidad de soporte de la consola de InHand Networks InRouter302 V3.5.45. Una solicitud de red especialmente manipulada puede conducir a la ejecución de un comando arbitr... • https://inhandnetworks.com/upload/attachment/202210/25/InHand-PSA-2022-02.pdf • CWE-489: Active Debug Code •
CVE-2022-26023
https://notcve.org/view.php?id=CVE-2022-26023
09 Nov 2022 — A leftover debug code vulnerability exists in the console verify functionality of InHand Networks InRouter302 V3.5.45. A specially-crafted series of network requests can lead to disabling security features. An attacker can send a sequence of requests to trigger this vulnerability. Existe una vulnerabilidad de código de depuración sobrante en la funcionalidad de verificación de la consola de InHand Networks InRouter302 V3.5.45. Una serie de solicitudes de red especialmente manipuladas pueden provocar la desa... • https://inhandnetworks.com/upload/attachment/202210/25/InHand-PSA-2022-02.pdf • CWE-489: Active Debug Code •
CVE-2022-27172
https://notcve.org/view.php?id=CVE-2022-27172
12 May 2022 — A hard-coded password vulnerability exists in the console infactory functionality of InHand Networks InRouter302 V3.5.37. A specially-crafted network request can lead to privileged operation execution. An attacker can send a sequence of requests to trigger this vulnerability. Se presenta una vulnerabilidad en la contraseña embebida en la funcionalidad console infactory de InHand Networks InRouter302 versión V3.5.37. Una petición de red especialmente diseñada puede conllevar a una ejecución de operaciones pr... • https://talosintelligence.com/vulnerability_reports/TALOS-2022-1496 • CWE-259: Use of Hard-coded Password CWE-798: Use of Hard-coded Credentials •
CVE-2022-26782
https://notcve.org/view.php?id=CVE-2022-26782
12 May 2022 — Multiple improper input validation vulnerabilities exists in the libnvram.so nvram_import functionality of InHand Networks InRouter302 V3.5.4. A specially-crafted file can lead to remote code execution. An attacker can send a sequence of requests to trigger this vulnerability.An improper input validation vulnerability exists in the `httpd`'s `user_define_set_item` function. Controlling the `user_define_timeout` nvram variable can lead to remote code execution. Se presentan múltiples vulnerabilidades de comp... • https://talosintelligence.com/vulnerability_reports/TALOS-2022-1481 • CWE-20: Improper Input Validation CWE-787: Out-of-bounds Write •
CVE-2022-26781
https://notcve.org/view.php?id=CVE-2022-26781
12 May 2022 — Multiple improper input validation vulnerabilities exists in the libnvram.so nvram_import functionality of InHand Networks InRouter302 V3.5.4. A specially-crafted file can lead to remote code execution. An attacker can send a sequence of requests to trigger this vulnerability.An improper input validation vulnerability exists in the `httpd`'s `user_define_print` function. Controlling the `user_define_timeout` nvram variable can lead to remote code execution. Se presentan múltiples vulnerabilidades de comprob... • https://talosintelligence.com/vulnerability_reports/TALOS-2022-1481 • CWE-20: Improper Input Validation CWE-787: Out-of-bounds Write •
CVE-2022-26780
https://notcve.org/view.php?id=CVE-2022-26780
12 May 2022 — Multiple improper input validation vulnerabilities exists in the libnvram.so nvram_import functionality of InHand Networks InRouter302 V3.5.4. A specially-crafted file can lead to remote code execution. An attacker can send a sequence of requests to trigger this vulnerability.An improper input validation vulnerability exists in the `httpd`'s `user_define_init` function. Controlling the `user_define_timeout` nvram variable can lead to remote code execution. Existen múltiples vulnerabilidades de comprobación ... • https://talosintelligence.com/vulnerability_reports/TALOS-2022-1481 • CWE-20: Improper Input Validation •
CVE-2022-26518
https://notcve.org/view.php?id=CVE-2022-26518
12 May 2022 — An OS command injection vulnerability exists in the console infactory_net functionality of InHand Networks InRouter302 V3.5.37. A specially-crafted series of network requests can lead to remote code execution. An attacker can send a sequence of requests to trigger this vulnerability. Se presenta una vulnerabilidad de inyección de comandos del Sistema Operativo en la funcionalidad infactory_net de la consola de InHand Networks InRouter302 versión V3.5.37. Una serie de peticiones de red especialmente diseñada... • https://talosintelligence.com/vulnerability_reports/TALOS-2022-1501 • CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') •