9 results (0.007 seconds)

CVSS: 8.8EPSS: 0%CPEs: 2EXPL: 1

12 May 2022 — A hard-coded password vulnerability exists in the console infactory functionality of InHand Networks InRouter302 V3.5.37. A specially-crafted network request can lead to privileged operation execution. An attacker can send a sequence of requests to trigger this vulnerability. Se presenta una vulnerabilidad en la contraseña embebida en la funcionalidad console infactory de InHand Networks InRouter302 versión V3.5.37. Una petición de red especialmente diseñada puede conllevar a una ejecución de operaciones pr... • https://talosintelligence.com/vulnerability_reports/TALOS-2022-1496 • CWE-259: Use of Hard-coded Password CWE-798: Use of Hard-coded Credentials •

CVSS: 9.9EPSS: 0%CPEs: 2EXPL: 1

12 May 2022 — Multiple improper input validation vulnerabilities exists in the libnvram.so nvram_import functionality of InHand Networks InRouter302 V3.5.4. A specially-crafted file can lead to remote code execution. An attacker can send a sequence of requests to trigger this vulnerability.An improper input validation vulnerability exists in the `httpd`'s `user_define_set_item` function. Controlling the `user_define_timeout` nvram variable can lead to remote code execution. Se presentan múltiples vulnerabilidades de comp... • https://talosintelligence.com/vulnerability_reports/TALOS-2022-1481 • CWE-20: Improper Input Validation CWE-787: Out-of-bounds Write •

CVSS: 9.9EPSS: 0%CPEs: 2EXPL: 1

12 May 2022 — Multiple improper input validation vulnerabilities exists in the libnvram.so nvram_import functionality of InHand Networks InRouter302 V3.5.4. A specially-crafted file can lead to remote code execution. An attacker can send a sequence of requests to trigger this vulnerability.An improper input validation vulnerability exists in the `httpd`'s `user_define_print` function. Controlling the `user_define_timeout` nvram variable can lead to remote code execution. Se presentan múltiples vulnerabilidades de comprob... • https://talosintelligence.com/vulnerability_reports/TALOS-2022-1481 • CWE-20: Improper Input Validation CWE-787: Out-of-bounds Write •

CVSS: 9.9EPSS: 0%CPEs: 2EXPL: 1

12 May 2022 — Multiple improper input validation vulnerabilities exists in the libnvram.so nvram_import functionality of InHand Networks InRouter302 V3.5.4. A specially-crafted file can lead to remote code execution. An attacker can send a sequence of requests to trigger this vulnerability.An improper input validation vulnerability exists in the `httpd`'s `user_define_init` function. Controlling the `user_define_timeout` nvram variable can lead to remote code execution. Existen múltiples vulnerabilidades de comprobación ... • https://talosintelligence.com/vulnerability_reports/TALOS-2022-1481 • CWE-20: Improper Input Validation •

CVSS: 9.1EPSS: 0%CPEs: 2EXPL: 1

12 May 2022 — An OS command injection vulnerability exists in the console factory functionality of InHand Networks InRouter302 V3.5.4. A specially-crafted network request can lead to command execution. An attacker can send a sequence of requests to trigger this vulnerability. Se presenta una vulnerabilidad de inyección de comandos del Sistema Operativo en la funcionalidad console factory de InHand Networks InRouter302 versión V3.5.4. Una petición de red especialmente diseñada puede conllevar a una ejecución de un comando... • https://talosintelligence.com/vulnerability_reports/TALOS-2022-1475 • CWE-77: Improper Neutralization of Special Elements used in a Command ('Command Injection') CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') •

CVSS: 9.1EPSS: 0%CPEs: 2EXPL: 1

12 May 2022 — A stack-based buffer overflow vulnerability exists in the console factory functionality of InHand Networks InRouter302 V3.5.4. A specially-crafted network request can lead to remote code execution. An attacker can send a sequence of malicious packets to trigger this vulnerability. Se presenta una vulnerabilidad de desbordamiento de búfer en la región stack de la memoria en la funcionalidad console factory de InHand Networks InRouter302 versión V3.5.4. Una petición de red especialmente diseñada puede conllev... • https://talosintelligence.com/vulnerability_reports/TALOS-2022-1476 • CWE-121: Stack-based Buffer Overflow CWE-787: Out-of-bounds Write •

CVSS: 9.9EPSS: 0%CPEs: 2EXPL: 1

12 May 2022 — A command execution vulnerability exists in the console inhand functionality of InHand Networks InRouter302 V3.5.4. A specially-crafted network request can lead to arbitrary command execution. An attacker can send a sequence of requests to trigger this vulnerability. Se presenta una vulnerabilidad de ejecución de comandos en la funcionalidad console inhand de InHand Networks InRouter302 versión V3.5.4. Una petición de red especialmente diseñada puede conllevar a una ejecución de un comando arbitrario. • https://talosintelligence.com/vulnerability_reports/TALOS-2022-1477 • CWE-489: Active Debug Code •

CVSS: 7.5EPSS: 0%CPEs: 2EXPL: 1

12 May 2022 — An information disclosure vulnerability exists in the web interface session cookie functionality of InHand Networks InRouter302 V3.5.4. The session cookie misses the HttpOnly flag, making it accessible via JavaScript and thus allowing an attacker, able to perform an XSS attack, to steal the session cookie. Se presenta una vulnerabilidad de divulgación de información en la funcionalidad web interface session cookie de InHand Networks InRouter302 versión V3.5.4. La cookie de sesión carece del flag HttpOnly, h... • https://talosintelligence.com/vulnerability_reports/TALOS-2022-1470 • CWE-732: Incorrect Permission Assignment for Critical Resource CWE-1004: Sensitive Cookie Without 'HttpOnly' Flag •

CVSS: 8.2EPSS: 0%CPEs: 2EXPL: 1

12 May 2022 — A buffer overflow vulnerability exists in the httpd parse_ping_result API functionality of InHand Networks InRouter302 V3.5.4. A specially-crafted file can lead to remote code execution. An attacker can send a sequence of requests to trigger this vulnerability. Se presenta una vulnerabilidad de desbordamiento de búfer en la funcionalidad de la API httpd parse_ping_result de InHand Networks InRouter302 versión V3.5.4. Un archivo especialmente diseñado puede conllevar a una ejecución de código remota. • https://talosintelligence.com/vulnerability_reports/TALOS-2022-1471 • CWE-120: Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') •