Evenroute

Iqrouter Firmware

6 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.85%
  • Veröffentlicht 21.04.2020 13:15:15
  • Zuletzt bearbeitet 21.11.2024 04:59:00

In IQrouter through 3.3.1, remote attackers can control the device (restart network, reboot, upgrade, reset) because of Incorrect Access Control. Note: The vendor claims that this vulnerability can only occur on a brand-new network that, after initia...

  • EPSS 0.69%
  • Veröffentlicht 21.04.2020 13:15:15
  • Zuletzt bearbeitet 21.11.2024 04:59:00

In the web-panel in IQrouter through 3.3.1, remote attackers can read system logs because of Incorrect Access Control. Note: The vendor claims that this vulnerability can only occur on a brand-new network that, after initiating the forced initial con...

  • EPSS 0.72%
  • Veröffentlicht 21.04.2020 13:15:14
  • Zuletzt bearbeitet 21.11.2024 04:58:59

IQrouter through 3.3.1, when unconfigured, has multiple remote code execution vulnerabilities in the web-panel because of Bash Shell Metacharacter Injection. Note: The vendor claims that this vulnerability can only occur on a brand-new network that, ...

  • EPSS 0.59%
  • Veröffentlicht 21.04.2020 13:15:14
  • Zuletzt bearbeitet 21.11.2024 04:59:00

In IQrouter through 3.3.1, the Lua function diag_set_password in the web-panel allows remote attackers to change the root password arbitrarily. Note: The vendor claims that this vulnerability can only occur on a brand-new network that, after initiati...

  • EPSS 0.43%
  • Veröffentlicht 21.04.2020 13:15:14
  • Zuletzt bearbeitet 21.11.2024 04:59:00

In IQrouter through 3.3.1, there is a root user without a password, which allows attackers to gain full remote access via SSH. Note: The vendor claims that this vulnerability can only occur on a brand-new network that, after initiating the forced ini...

  • EPSS 0.81%
  • Veröffentlicht 21.04.2020 13:15:14
  • Zuletzt bearbeitet 21.11.2024 04:59:00

In IQrouter through 3.3.1, the Lua function reset_password in the web-panel allows remote attackers to change the root password arbitrarily. Note: The vendor claims that this vulnerability can only occur on a brand-new network that, after initiating ...