Vulnerabilities

DATE CVE VULNERABILITY TITLE RISK
2015-12-31 CVE-2015-6019 Unspecified vulnerability in Zyxel Pmg5318-B20A Firmware V100Aanc0B5
The management portal on ZyXEL PMG5318-B20A devices with firmware 1.00AANC0b5 does not terminate sessions upon a logout action, which allows remote attackers to bypass intended access restrictions by leveraging an unattended workstation.
network
low complexity
zyxel
8.5
2015-12-31 CVE-2015-6018 Permissions, Privileges, and Access Controls vulnerability in Zyxel Pmg5318-B20A Firmware V100Aanc0B5
The diagnostic-ping implementation on ZyXEL PMG5318-B20A devices with firmware before 1.00(AANC.2)C0 allows remote attackers to execute arbitrary commands via the PingIPAddr parameter.
network
low complexity
zyxel CWE-264
critical
9.8
2015-12-31 CVE-2015-6017 Cross-site Scripting vulnerability in Zyxel P-660Hw-T1 V2 Firmware 3.40(Axh.0)
Multiple cross-site scripting (XSS) vulnerabilities in Forms/rpAuth_1 on ZyXEL P-660HW-T1 2 devices with ZyNOS firmware 3.40(AXH.0) allow remote attackers to inject arbitrary web script or HTML via the (1) LoginPassword or (2) hiddenPassword parameter.
network
low complexity
zyxel CWE-79
6.1
2015-12-31 CVE-2015-6016 Credentials Management vulnerability in Zyxel Nbg-418N, Pmg5318-B20A Firmware and Zynos Firmware
ZyXEL P-660HW-T1 2 devices with ZyNOS firmware 3.40(AXH.0), PMG5318-B20A devices with firmware 1.00AANC0b5, and NBG-418N devices have a default password of 1234 for the admin account, which allows remote attackers to obtain administrative access via unspecified vectors.
network
low complexity
zyxel CWE-255
critical
9.8
2015-12-31 CVE-2015-5996 Cross-Site Request Forgery (CSRF) vulnerability in Mediabridge Medialink Mwn-Wapr300N Firmware 5.07.50
Cross-site request forgery (CSRF) vulnerability on Mediabridge Medialink MWN-WAPR300N devices with firmware 5.07.50 allows remote attackers to hijack the authentication of arbitrary users.
network
low complexity
mediabridge CWE-352
8.8
2015-12-31 CVE-2015-5995 Permissions, Privileges, and Access Controls vulnerability in multiple products
Mediabridge Medialink MWN-WAPR300N devices with firmware 5.07.50 and Tenda N3 Wireless N150 devices allow remote attackers to obtain administrative access via a certain admin substring in an HTTP Cookie header.
network
low complexity
tenda mediabridge CWE-264
critical
9.8
2015-12-31 CVE-2015-5994 Credentials Management vulnerability in Mediabridge Medialink Mwn-Wapr300N Firmware 5.07.50
The web management interface on Mediabridge Medialink MWN-WAPR300N devices with firmware 5.07.50 has a default password of admin for the admin account and a default password of password for the medialink account, which allows remote attackers to obtain administrative privileges by leveraging a Wi-Fi session.
low complexity
mediabridge CWE-255
6.8
2015-12-31 CVE-2015-2918 Improper Input Validation vulnerability in Orientdb 2.0.14/2.1.0
The Studio component in OrientDB Server Community Edition before 2.0.15 and 2.1.x before 2.1.1 does not properly restrict use of FRAME elements, which makes it easier for remote attackers to conduct clickjacking attacks via a crafted web site.
network
low complexity
orientdb CWE-20
6.1
2015-12-31 CVE-2015-2913 Information Exposure vulnerability in Orientdb 2.0.14/2.1.0
server/network/protocol/http/OHttpSessionManager.java in the Studio component in OrientDB Server Community Edition before 2.0.15 and 2.1.x before 2.1.1 improperly relies on the java.util.Random class for generation of random Session ID values, which makes it easier for remote attackers to predict a value by determining the internal state of the PRNG in this class.
network
high complexity
orientdb CWE-200
5.9
2015-12-31 CVE-2015-2912 Cross-Site Request Forgery (CSRF) vulnerability in Orientdb 2.0.14/2.1.0
The JSONP endpoint in the Studio component in OrientDB Server Community Edition before 2.0.15 and 2.1.x before 2.1.1 does not properly restrict callback values, which allows remote attackers to conduct cross-site request forgery (CSRF) attacks, and obtain sensitive information, via a crafted HTTP request.
network
low complexity
orientdb CWE-352
8.8