Vulnerabilities > Ampedwireless

DATE CVE VULNERABILITY TITLE RISK
2015-12-31 CVE-2015-7279 Cross-Site Request Forgery vulnerability in Ampedwireless R10000 Firmware 2.5.2.11
Amped Wireless R10000 devices with firmware 2.5.2.11 use an improper algorithm for selecting the ID value in the header of a DNS query, which makes it easier for remote attackers to spoof responses by predicting this value.
network
low complexity
ampedwireless
5.0
2015-12-31 CVE-2015-7278 Cross-Site Request Forgery (CSRF) vulnerability in Ampedwireless R10000 Firmware 2.5.2.11
Cross-site request forgery (CSRF) vulnerability on Amped Wireless R10000 devices with firmware 2.5.2.11 allows remote attackers to hijack the authentication of arbitrary users.
6.8
2015-12-31 CVE-2015-7277 Credentials Management vulnerability in Ampedwireless R10000 Firmware 2.5.2.11
The web administration interface on Amped Wireless R10000 devices with firmware 2.5.2.11 has a default password of admin for the admin account, which allows remote attackers to obtain administrative privileges by leveraging a LAN session.
network
ampedwireless CWE-255
critical
9.3