CVE-2026-44874
- EPSS 0.03%
- Veröffentlicht 12.05.2026 19:19:25
- Zuletzt bearbeitet 15.05.2026 12:44:39
A vulnerability exists in the web-based management interface of an AOS-10 Gateway that could allow an authenticated remote attacker to access sensitive files on the underlying operating system. Successful exploitation of this vulnerability could resu...
CVE-2026-44863
- EPSS 0.03%
- Veröffentlicht 12.05.2026 19:09:19
- Zuletzt bearbeitet 14.05.2026 18:40:48
SQL injection vulnerabilities exist in several underlying service components accessible through the AOS-8 and AOS-10 command-line interface and management protocol. An authenticated attacker with administrative privileges could exploit these vulnerab...
CVE-2026-44862
- EPSS 0.03%
- Veröffentlicht 12.05.2026 19:08:16
- Zuletzt bearbeitet 14.05.2026 18:41:00
SQL injection vulnerabilities exist in several underlying service components accessible through the AOS-8 and AOS-10 command-line interface and management protocol. An authenticated attacker with administrative privileges could exploit these vulnerab...
CVE-2026-44861
- EPSS 0.03%
- Veröffentlicht 12.05.2026 19:06:35
- Zuletzt bearbeitet 14.05.2026 18:41:11
SQL injection vulnerabilities exist in several underlying service components accessible through the AOS-8 and AOS-10 command-line interface and management protocol. An authenticated attacker with administrative privileges could exploit these vulnerab...
CVE-2026-44852
- EPSS 0.09%
- Veröffentlicht 12.05.2026 18:55:53
- Zuletzt bearbeitet 15.05.2026 21:16:36
An authenticated remote code execution vulnerability exists in the AOS-8 and AOS-10 web-based management interface. A vulnerability in the certificate download functionality could allow an authenticated remote attacker to overwrite arbitrary files on...
CVE-2026-23827
- EPSS 0.12%
- Veröffentlicht 12.05.2026 18:54:47
- Zuletzt bearbeitet 15.05.2026 12:45:03
A heap-based buffer overflow vulnerability exists in a Network management service of AOS-8 and AOS-10 that could allow an unauthenticated remote attacker to achieve remote code execution. Successful exploitation could allow an unauthenticated attacke...
CVE-2026-23823
- EPSS 0.19%
- Veröffentlicht 12.05.2026 18:38:44
- Zuletzt bearbeitet 13.05.2026 15:35:17
A vulnerability in the command line interface of Access Points running AOS-10 could allow an authenticated remote attacker to perform command injection. Successful exploitation could allow an attacker to execute arbitrary commands on the underlying o...
CVE-2026-23822
- EPSS 0.07%
- Veröffentlicht 12.05.2026 18:37:08
- Zuletzt bearbeitet 13.05.2026 15:35:17
A vulnerability in the XML handling component of AOS-8 DHCP services could allow an unauthenticated remote attacker to trigger a denial-of-service condition. Successful exploitation could allow an attacker to cause excessive resource consumption upon...
CVE-2026-23821
- EPSS 0.12%
- Veröffentlicht 12.05.2026 18:35:34
- Zuletzt bearbeitet 13.05.2026 15:35:17
A vulnerability in the configuration processing logic of Access Points running AOS-10 could allow an authenticated remote attacker to execute system commands under certain pre-existing conditions. Successful exploitation could allow an attacker to ex...
CVE-2026-23820
- EPSS 0.12%
- Veröffentlicht 12.05.2026 18:34:34
- Zuletzt bearbeitet 13.05.2026 15:35:17
A vulnerability in the command line interface of Access Points running AOS-10 and AOS-8 Instant could allow an authenticated remote attacker to execute system commands in a restricted shell environment. Successful exploitation could allow an attacker...