CVE-2022-27172
https://notcve.org/view.php?id=CVE-2022-27172
12 May 2022 — A hard-coded password vulnerability exists in the console infactory functionality of InHand Networks InRouter302 V3.5.37. A specially-crafted network request can lead to privileged operation execution. An attacker can send a sequence of requests to trigger this vulnerability. Se presenta una vulnerabilidad en la contraseña embebida en la funcionalidad console infactory de InHand Networks InRouter302 versión V3.5.37. Una petición de red especialmente diseñada puede conllevar a una ejecución de operaciones pr... • https://talosintelligence.com/vulnerability_reports/TALOS-2022-1496 • CWE-259: Use of Hard-coded Password CWE-798: Use of Hard-coded Credentials •
CVE-2022-26782
https://notcve.org/view.php?id=CVE-2022-26782
12 May 2022 — Multiple improper input validation vulnerabilities exists in the libnvram.so nvram_import functionality of InHand Networks InRouter302 V3.5.4. A specially-crafted file can lead to remote code execution. An attacker can send a sequence of requests to trigger this vulnerability.An improper input validation vulnerability exists in the `httpd`'s `user_define_set_item` function. Controlling the `user_define_timeout` nvram variable can lead to remote code execution. Se presentan múltiples vulnerabilidades de comp... • https://talosintelligence.com/vulnerability_reports/TALOS-2022-1481 • CWE-20: Improper Input Validation CWE-787: Out-of-bounds Write •
CVE-2022-26781
https://notcve.org/view.php?id=CVE-2022-26781
12 May 2022 — Multiple improper input validation vulnerabilities exists in the libnvram.so nvram_import functionality of InHand Networks InRouter302 V3.5.4. A specially-crafted file can lead to remote code execution. An attacker can send a sequence of requests to trigger this vulnerability.An improper input validation vulnerability exists in the `httpd`'s `user_define_print` function. Controlling the `user_define_timeout` nvram variable can lead to remote code execution. Se presentan múltiples vulnerabilidades de comprob... • https://talosintelligence.com/vulnerability_reports/TALOS-2022-1481 • CWE-20: Improper Input Validation CWE-787: Out-of-bounds Write •
CVE-2022-26780
https://notcve.org/view.php?id=CVE-2022-26780
12 May 2022 — Multiple improper input validation vulnerabilities exists in the libnvram.so nvram_import functionality of InHand Networks InRouter302 V3.5.4. A specially-crafted file can lead to remote code execution. An attacker can send a sequence of requests to trigger this vulnerability.An improper input validation vulnerability exists in the `httpd`'s `user_define_init` function. Controlling the `user_define_timeout` nvram variable can lead to remote code execution. Existen múltiples vulnerabilidades de comprobación ... • https://talosintelligence.com/vulnerability_reports/TALOS-2022-1481 • CWE-20: Improper Input Validation •
CVE-2022-26007
https://notcve.org/view.php?id=CVE-2022-26007
12 May 2022 — An OS command injection vulnerability exists in the console factory functionality of InHand Networks InRouter302 V3.5.4. A specially-crafted network request can lead to command execution. An attacker can send a sequence of requests to trigger this vulnerability. Se presenta una vulnerabilidad de inyección de comandos del Sistema Operativo en la funcionalidad console factory de InHand Networks InRouter302 versión V3.5.4. Una petición de red especialmente diseñada puede conllevar a una ejecución de un comando... • https://talosintelligence.com/vulnerability_reports/TALOS-2022-1475 • CWE-77: Improper Neutralization of Special Elements used in a Command ('Command Injection') CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') •
CVE-2022-26002
https://notcve.org/view.php?id=CVE-2022-26002
12 May 2022 — A stack-based buffer overflow vulnerability exists in the console factory functionality of InHand Networks InRouter302 V3.5.4. A specially-crafted network request can lead to remote code execution. An attacker can send a sequence of malicious packets to trigger this vulnerability. Se presenta una vulnerabilidad de desbordamiento de búfer en la región stack de la memoria en la funcionalidad console factory de InHand Networks InRouter302 versión V3.5.4. Una petición de red especialmente diseñada puede conllev... • https://talosintelligence.com/vulnerability_reports/TALOS-2022-1476 • CWE-121: Stack-based Buffer Overflow CWE-787: Out-of-bounds Write •
CVE-2022-25995
https://notcve.org/view.php?id=CVE-2022-25995
12 May 2022 — A command execution vulnerability exists in the console inhand functionality of InHand Networks InRouter302 V3.5.4. A specially-crafted network request can lead to arbitrary command execution. An attacker can send a sequence of requests to trigger this vulnerability. Se presenta una vulnerabilidad de ejecución de comandos en la funcionalidad console inhand de InHand Networks InRouter302 versión V3.5.4. Una petición de red especialmente diseñada puede conllevar a una ejecución de un comando arbitrario. • https://talosintelligence.com/vulnerability_reports/TALOS-2022-1477 • CWE-489: Active Debug Code •
CVE-2022-25172
https://notcve.org/view.php?id=CVE-2022-25172
12 May 2022 — An information disclosure vulnerability exists in the web interface session cookie functionality of InHand Networks InRouter302 V3.5.4. The session cookie misses the HttpOnly flag, making it accessible via JavaScript and thus allowing an attacker, able to perform an XSS attack, to steal the session cookie. Se presenta una vulnerabilidad de divulgación de información en la funcionalidad web interface session cookie de InHand Networks InRouter302 versión V3.5.4. La cookie de sesión carece del flag HttpOnly, h... • https://talosintelligence.com/vulnerability_reports/TALOS-2022-1470 • CWE-732: Incorrect Permission Assignment for Critical Resource CWE-1004: Sensitive Cookie Without 'HttpOnly' Flag •
CVE-2022-24910
https://notcve.org/view.php?id=CVE-2022-24910
12 May 2022 — A buffer overflow vulnerability exists in the httpd parse_ping_result API functionality of InHand Networks InRouter302 V3.5.4. A specially-crafted file can lead to remote code execution. An attacker can send a sequence of requests to trigger this vulnerability. Se presenta una vulnerabilidad de desbordamiento de búfer en la funcionalidad de la API httpd parse_ping_result de InHand Networks InRouter302 versión V3.5.4. Un archivo especialmente diseñado puede conllevar a una ejecución de código remota. • https://talosintelligence.com/vulnerability_reports/TALOS-2022-1471 • CWE-120: Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') •