Vulnerabilities > Belkin

DATE CVE VULNERABILITY TITLE RISK
2012-11-20 CVE-2012-4366 Cryptographic Issues vulnerability in Belkin products
Belkin wireless routers Surf N150 Model F7D1301v1, N900 Model F9K1104v1, N450 Model F9K1105V2, and N300 Model F7D2301v1 generate a predictable default WPA2-PSK passphrase based on eight digits of the WAN MAC address, which allows remote attackers to access the network by sniffing the beacon frames.
low complexity
belkin CWE-310
3.3
2009-08-28 CVE-2008-7115 Permissions, Privileges, and Access Controls vulnerability in Belkin F5D7632-4 and Wireless G Router
The web interface to the Belkin Wireless G router and ADSL2 modem F5D7632-4V6 with firmware 6.01.08 allows remote attackers to bypass authentication and gain administrator privileges via a direct request to (1) statusprocess.exe, (2) system_all.exe, or (3) restore.exe in cgi-bin/.
network
low complexity
belkin CWE-264
critical
10.0
2008-03-10 CVE-2008-1245 Improper Input Validation vulnerability in Belkin F5D7230-4
cgi-bin/setup_virtualserver.exe on the Belkin F5D7230-4 router with firmware 9.01.10 allows remote attackers to cause a denial of service (control center outage) via an HTTP request with invalid POST data and a "Connection: Keep-Alive" header.
network
low complexity
belkin CWE-20
7.8
2008-03-10 CVE-2008-1244 Improper Authentication vulnerability in Belkin F5D7230-4
cgi-bin/setup_dns.exe on the Belkin F5D7230-4 router with firmware 9.01.10 does not require authentication, which allows remote attackers to perform administrative actions, as demonstrated by changing a DNS server via the dns1_1, dns1_2, dns1_3, and dns1_4 parameters.
network
low complexity
belkin CWE-287
critical
10.0
2008-03-10 CVE-2008-1242 Permissions, Privileges, and Access Controls vulnerability in Belkin F5D7230-4
The control panel on the Belkin F5D7230-4 router with firmware 9.01.10 maintains authentication state by IP address, which allows remote attackers to bypass authentication by establishing a session from a source IP address of a previously authenticated user, a different vulnerability than CVE-2005-3802.
network
low complexity
belkin CWE-264
critical
10.0
2008-01-23 CVE-2008-0403 Improper Authentication vulnerability in Belkin F5D9230-4
The web server in Belkin Wireless G Plus MIMO Router F5D9230-4 does not require authentication for SaveCfgFile.cgi, which allows remote attackers to read and modify configuration via a direct request to SaveCfgFile.cgi.
network
low complexity
belkin CWE-287
5.5
2007-11-20 CVE-2007-6040 Resource Management Errors vulnerability in Belkin F5D7230-4
The Belkin F5D7230-4 Wireless G Router allows remote attackers to cause a denial of service (degraded networking and logging) via a flood of TCP SYN packets, a related issue to CVE-1999-0116.
network
low complexity
belkin CWE-399
5.0
2007-07-15 CVE-2007-3784 HTML Injection vulnerability in Belkin F5D7231-4 Firmware4.05.03
Cross-site scripting (XSS) vulnerability in the Belkin G Plus Router F5D7231-4 with firmware 4.05.03 allows remote attackers to inject arbitrary web script or HTML via a hostname of a DHCP client.
network
belkin
4.3
2005-12-20 CVE-2005-4417 Remote Security vulnerability in Blue Usb-130-250 Software
The default configuration of Widcomm Bluetooth for Windows (BTW) 4.0.1.1500 and earlier, as installed on Belkin Bluetooth Software 1.4.2 Build 10 and ANYCOM Blue USB-130-250 Software 4.0.1.1500, and possibly other devices, sets null Authentication and Authorization values, which allows remote attackers to send arbitrary audio and possibly eavesdrop using the microphone via the Hands Free Audio Gateway and Headset profile.
network
low complexity
anycom belkin widcomm
6.4
2005-11-24 CVE-2005-3802 Unspecified vulnerability in Belkin F5D7230-4 and F5D7232-4
Belkin F5D7232-4 and F5D7230-4 wireless routers with firmware 4.03.03 and 4.05.03, when a legitimate administrator is logged into the web management interface, allow remote attackers to access the management interface without authentication.
network
high complexity
belkin
5.1