Hot

Hotbox Router

6 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.66%
  • Veröffentlicht 30.12.2013 04:53:07
  • Zuletzt bearbeitet 11.04.2025 00:51:21

The HOT HOTBOX router with software 2.1.11 has a default WPS PIN of 12345670, which makes it easier for remote attackers to obtain the WPA or WPA2 pre-shared key via EAP messages.

Exploit
  • EPSS 1%
  • Veröffentlicht 30.12.2013 04:53:07
  • Zuletzt bearbeitet 11.04.2025 00:51:21

The HOT HOTBOX router with software 2.1.11 allows remote attackers to bypass authentication by configuring a source IP address that had previously been used for an authenticated session.

Exploit
  • EPSS 0.31%
  • Veröffentlicht 30.12.2013 04:53:07
  • Zuletzt bearbeitet 11.04.2025 00:51:21

Cross-site request forgery (CSRF) vulnerability in goform/wlanBasicSecurity on the HOT HOTBOX router with software 2.1.11 allows remote attackers to hijack the authentication of administrators for requests that change the WiFi Security field to Deact...

Exploit
  • EPSS 0.82%
  • Veröffentlicht 30.12.2013 04:53:07
  • Zuletzt bearbeitet 11.04.2025 00:51:21

Cross-site scripting (XSS) vulnerability on the HOT HOTBOX router with software 2.1.11 allows remote attackers to inject arbitrary web script or HTML via a crafted DHCP Host Name option, which is not properly handled during rendering of the DHCP tabl...

Exploit
  • EPSS 1.5%
  • Veröffentlicht 30.12.2013 04:53:07
  • Zuletzt bearbeitet 11.04.2025 00:51:21

Directory traversal vulnerability on the HOT HOTBOX router with software 2.1.11 allows remote attackers to read arbitrary files via a .. (dot dot) in a URI, as demonstrated by a request for /etc/passwd.

Exploit
  • EPSS 1.56%
  • Veröffentlicht 30.12.2013 04:53:07
  • Zuletzt bearbeitet 11.04.2025 00:51:21

goform/login on the HOT HOTBOX router with software 2.1.11 allows remote attackers to cause a denial of service (device crash) via crafted HTTP POST data.