NA - CVE-2024-42736 - In TOTOLINK X5000r v9.1.0cu.2350_b20230313, the...
In TOTOLINK X5000r v9.1.0cu.2350_b20230313, the file /cgi-bin/cstecgi.cgi contains an OS command injection vulnerability in addBlacklist. Authenticated Attackers can send malicious packet to...
High - CVE-2024-42737 - In TOTOLINK X5000r v9.1.0cu.2350_b20230313, the...
In TOTOLINK X5000r v9.1.0cu.2350_b20230313, the file /cgi-bin/cstecgi.cgi contains an OS command injection vulnerability in delBlacklist. Authenticated Attackers can send malicious packet to...
High - CVE-2024-42738 - In TOTOLINK X5000r v9.1.0cu.2350_b20230313, the...
In TOTOLINK X5000r v9.1.0cu.2350_b20230313, the file /cgi-bin/cstecgi.cgi contains an OS command injection vulnerability in setDmzCfg. Authenticated Attackers can send malicious packet to execute...
High - CVE-2024-42739 - In TOTOLINK X5000r v9.1.0cu.2350_b20230313, the...
In TOTOLINK X5000r v9.1.0cu.2350_b20230313, the file /cgi-bin/cstecgi.cgi contains an OS command injection vulnerability in setAccessDeviceCfg. Authenticated Attackers can send malicious packet to...
NA - CVE-2024-42740 - In TOTOLINK X5000r v9.1.0cu.2350_b20230313, the...
In TOTOLINK X5000r v9.1.0cu.2350_b20230313, the file /cgi-bin/cstecgi.cgi contains an OS command injection vulnerability in setLedCfg. Authenticated Attackers can send malicious packet to execute...
High - CVE-2024-6788 - A remote unauthenticated attacker can use the...
A remote unauthenticated attacker can use the firmware update feature on the LAN interface of the device to reset the password for the predefined, low-privileged user “user-app” to the default...
NA - CVE-2024-6384 - "Hot" backup files may be downloaded by...
"Hot" backup files may be downloaded by underprivileged users, if they are capable of acquiring a unique backup identifier. This issue affects MongoDB Enterprise Server v6.0 versions prior to...
NA - CVE-2022-27486 - A improper neutralization of special elements...
A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiDDoS version 5.5.0 through 5.5.1, 5.4.2 through 5.4.0, 5.3.0 through 5.3.1,...
NA - CVE-2022-45862 - An insufficient session expiration...
An insufficient session expiration vulnerability [CWE-613] vulnerability in FortiOS 7.2.5 and below, 7.0 all versions, 6.4 all versions; FortiProxy 7.2 all versions, 7.0 all versions; FortiPAM 1.3...
NA - CVE-2023-26211 - An improper neutralization of input during web...
An improper neutralization of input during web page generation ('cross-site scripting') in Fortinet FortiSOAR 7.3.0 through 7.3.2 allows an authenticated, remote attacker to inject...