Vulnerabilities > Carrier > Critical

DATE CVE VULNERABILITY TITLE RISK
2022-06-06 CVE-2022-31479 OS Command Injection vulnerability in multiple products
An unauthenticated attacker can update the hostname with a specially crafted name that will allow for shell commands to be executed during the core collection process.
network
low complexity
hidglobal carrier CWE-78
critical
9.8
2022-06-06 CVE-2022-31483 Path Traversal vulnerability in multiple products
An authenticated attacker can upload a file with a filename including “..” and “/” to achieve the ability to upload the desired file anywhere on the filesystem.
network
low complexity
hidglobal carrier CWE-22
critical
9.0
2022-06-06 CVE-2022-31486 OS Command Injection vulnerability in multiple products
An authenticated attacker can send a specially crafted route to the “edit_route.cgi” binary and have it execute shell commands.
network
low complexity
hidglobal carrier CWE-78
critical
9.0