Sick

Tdc-x401gl Firmware

14 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.05%
  • Veröffentlicht 15.01.2026 13:16:07
  • Zuletzt bearbeitet 23.01.2026 18:36:58

The device's passwords have not been adequately salted, making them vulnerable to password extraction attacks.

  • EPSS 0.04%
  • Veröffentlicht 15.01.2026 13:16:06
  • Zuletzt bearbeitet 23.01.2026 15:30:41

Improper handling of a URL parameter may allow attackers to execute code in a user's browser after login. This can lead to the extraction of sensitive data.

  • EPSS 0.03%
  • Veröffentlicht 15.01.2026 13:16:06
  • Zuletzt bearbeitet 23.01.2026 15:27:45

An attacker with limited permissions may still be able to write files to specific locations on the device, potentially leading to system manipulation.

  • EPSS 0.05%
  • Veröffentlicht 15.01.2026 13:16:06
  • Zuletzt bearbeitet 23.01.2026 15:17:20

An attacker with low privileges may be able to read files from specific directories on the device, potentially exposing sensitive information.

  • EPSS 0.05%
  • Veröffentlicht 15.01.2026 13:16:06
  • Zuletzt bearbeitet 23.01.2026 15:13:01

An attacker with low privileges may be able to trigger critical system functions such as reboot or factory reset without proper restrictions, potentially leading to service disruption or loss of configuration.

  • EPSS 0.08%
  • Veröffentlicht 15.01.2026 13:16:06
  • Zuletzt bearbeitet 23.01.2026 14:59:11

Improper input handling in a system endpoint may allow attackers to overload resources, causing a denial of service.

  • EPSS 0.05%
  • Veröffentlicht 15.01.2026 13:16:06
  • Zuletzt bearbeitet 23.01.2026 18:41:25

An attacker may exploit missing protection against clickjacking by tricking users into performing unintended actions through maliciously crafted web pages, leading to the extraction of sensitive data.

  • EPSS 0.04%
  • Veröffentlicht 15.01.2026 13:16:06
  • Zuletzt bearbeitet 23.01.2026 18:39:18

An attacker with administrative access may inject malicious content into the login page, potentially enabling cross-site scripting (XSS) attacks, leading to the extraction of sensitive data.

  • EPSS 0.05%
  • Veröffentlicht 15.01.2026 13:16:05
  • Zuletzt bearbeitet 23.01.2026 15:49:41

An attacker may gain unauthorized access to the host filesystem, potentially allowing them to read and modify system data.

  • EPSS 0.08%
  • Veröffentlicht 15.01.2026 13:16:05
  • Zuletzt bearbeitet 23.01.2026 15:46:56

Uploading unvalidated container images may allow remote attackers to gain full access to the system, potentially compromising its integrity and confidentiality.