CVE-2013-5037
- EPSS 0.66%
- Veröffentlicht 30.12.2013 04:53:07
- Zuletzt bearbeitet 11.04.2025 00:51:21
The HOT HOTBOX router with software 2.1.11 has a default WPS PIN of 12345670, which makes it easier for remote attackers to obtain the WPA or WPA2 pre-shared key via EAP messages.
CVE-2013-5038
- EPSS 1%
- Veröffentlicht 30.12.2013 04:53:07
- Zuletzt bearbeitet 11.04.2025 00:51:21
The HOT HOTBOX router with software 2.1.11 allows remote attackers to bypass authentication by configuring a source IP address that had previously been used for an authenticated session.
CVE-2013-5039
- EPSS 0.31%
- Veröffentlicht 30.12.2013 04:53:07
- Zuletzt bearbeitet 11.04.2025 00:51:21
Cross-site request forgery (CSRF) vulnerability in goform/wlanBasicSecurity on the HOT HOTBOX router with software 2.1.11 allows remote attackers to hijack the authentication of administrators for requests that change the WiFi Security field to Deact...
CVE-2013-5218
- EPSS 0.82%
- Veröffentlicht 30.12.2013 04:53:07
- Zuletzt bearbeitet 11.04.2025 00:51:21
Cross-site scripting (XSS) vulnerability on the HOT HOTBOX router with software 2.1.11 allows remote attackers to inject arbitrary web script or HTML via a crafted DHCP Host Name option, which is not properly handled during rendering of the DHCP tabl...
CVE-2013-5219
- EPSS 1.5%
- Veröffentlicht 30.12.2013 04:53:07
- Zuletzt bearbeitet 11.04.2025 00:51:21
Directory traversal vulnerability on the HOT HOTBOX router with software 2.1.11 allows remote attackers to read arbitrary files via a .. (dot dot) in a URI, as demonstrated by a request for /etc/passwd.
CVE-2013-5220
- EPSS 1.56%
- Veröffentlicht 30.12.2013 04:53:07
- Zuletzt bearbeitet 11.04.2025 00:51:21
goform/login on the HOT HOTBOX router with software 2.1.11 allows remote attackers to cause a denial of service (device crash) via crafted HTTP POST data.