Juplink RX4-1500 Stack-based Buffer Overflow Vulnerability

August 23, 2023 No Comments
EIP-b5185f25 A stack-based buffer overflow exists in Juplink RX4-1500, a WiFi router. An authenticated attacker can exploit this vulnerability to achieve code execution as root. Vulnerability Identifiers Exodus Intelligence: EIP-b5185f25 MITRE: CVE-2023-41028 Vulnerability Metrics CVSSv2 Vector: AV:A/AC:L/Au:S/C:C/I:C/A:C CVSSv2 Score: 7.7 Vendor References The affected product
Read More »

CloudLinux LVE kernel module (kmod-lve) Reference Counter Overflow

January 13, 2023 No Comments
EIP-ad32d249 A local privilege escalation vulnerability exists in the CloudLinux Lightweight Virtualized Environment (LVE) kernel module due to an overflow of a reference counter. Successful exploitation allows an authenticated local user to escalate their privileges to root, whereas an unsuccessful exploit may cause
Read More »

SonicWall SMA 500v and SMA 100 Series Firmware Heap Buffer Overflow

January 12, 2023 No Comments
EIP-6a6472ab A remote code execution vulnerability exists in SonicWall SMA 100 Series and SMA 500v Series due to a heap buffer overflow in the ‘extensionsetting’ endpoint. A remote, authenticated attacker can send crafted HTTP POST requests to execute code on vulnerable targets
Read More »

TP-Link WA850RE Unauthenticated Configuration Disclosure Vulnerability

June 23, 2022 No Comments
EIP-9098806c A vulnerability exists within the httpd server of the TP-Link WA850RE Universal Wi-Fi Range Extender that allows remote unauthenticated attackers to download the configuration file. Retrieval of this file results in the exposure of admin credentials and other sensitive information. Vulnerability
Read More »

TP-Link WA850RE Remote Command Injection Vulnerability

June 23, 2022 No Comments
EIP-7758d2d4 A vulnerability exists within the httpd server of the TP-Link WA850RE Universal Wi-Fi Range Extender that allows authenticated attackers to inject arbitrary commands as arguments to an execve() call due to a lack of input sanitization. Injected commands are executed with
Read More »

TP-Link WR940N/WR941ND Uninitialized Pointer Vulnerability

June 23, 2022 No Comments
EIP-9ad27c94 An uninitialized pointer vulnerability exists within TP-Link’s WR940N and WR941ND SOHO router devices specifically during the processing of UPnP/SOAP SUBSCRIBE requests. Successful exploitation allow local unauthenticated attackers the ability to execute arbitrary code under the context of the ‘root’ user. Vulnerability
Read More »

Mitel Web Management Interface Buffer Overflow Vulnerability

June 9, 2022 No Comments
EIP-c4542e4d A stack-based buffer overflow vulnerability exists within multiple Mitel product web management interfaces, including the 3300 Controller and MiVoice Business product lines. Improper handling of the ‘Lang’ query parameter allows remote unauthenticated attackers to execute arbitrary code. Vulnerability Identifiers Exodus Intelligence: EIP-c4542e4d
Read More »

SalesAgility SuiteCRM ‘deleteAttachment’ Type Confusion Vulnerability

June 9, 2022 No Comments
EIP-0077b802 A type confusion vulnerability exists within SalesAgility SuiteCRM within the processing of the ‘module’ parameter within the ‘deleteAttachment’ functionality. Successful exploitation allows remote unauthenticated attackers to alter database objects including changing the email address of the administrator. Vulnerability Identifiers Exodus Intelligence: EIP-0077b802
Read More »

SalesAgility SuiteCRM ‘export’ Request SQL Injection Vulnerability

June 9, 2022 No Comments
EIP-0f5d2d7f A SQL injection vulnerability exists within SalesAgility SuiteCRM within the processing of the ‘uid’ parameter within the ‘export’ functionality. Successful exploitation allows remote unauthenticated attackers to ultimately execute arbitrary code. Vulnerability Identifiers Exodus Intelligence: EIP-0f5d2d7f MITRE CVE: Pending Vulnerability Metrics CVSSv2 Score:
Read More »

D-Link DIR-1260 GetDeviceSettings Pre-Auth Command Injection Vulnerability

May 11, 2022 No Comments
EIP-3b20d7b3 A command injection vulnerability exists within the web management interface of the D-Link DIR-1260 Wi-Fi router that allows for unauthenticated attackers to execute arbitrary commands on the device with root privileges. The flaw specifically exists within the SetDest/Dest/Target arguments to the GetDeviceSettings
Read More »
1 3 4 5 7