Vulnerabilities > Chinamobileltd

DATE CVE VULNERABILITY TITLE RISK
2023-04-10 CVE-2023-26986 Unspecified vulnerability in Chinamobileltd OA Mailbox PC 2.9.23
An issue in China Mobile OA Mailbox PC v2.9.23 allows remote attackers to execute arbitrary commands on a victim host via user interaction with a crafted EML file sent to their OA mailbox.
local
low complexity
chinamobileltd
7.8
2023-01-26 CVE-2020-18330 Path Traversal vulnerability in Chinamobileltd Gpn2.4P21-C-Cn Firmware W2000En01
An issue was discovered in the default configuration of ChinaMobile PLC Wireless Router model GPN2.4P21-C-CN running the firmware version W2000EN-01(hardware platform Gpn2.4P21-C_WIFI-V0.05), allows attackers to gain access to the configuration interface.
network
low complexity
chinamobileltd CWE-22
critical
9.1
2023-01-26 CVE-2020-18331 Path Traversal vulnerability in Chinamobileltd Gpn2.4P21-C-Cn Firmware W2000En01
Directory traversal vulnerability in ChinaMobile PLC Wireless Router model GPN2.4P21-C-CN running the firmware version W2000EN-01(hardware platform Gpn2.4P21-C_WIFI-V0.05), via the getpage parameter to /cgi-bin/webproc.
network
low complexity
chinamobileltd CWE-22
critical
9.1
2022-01-14 CVE-2021-33962 OS Command Injection vulnerability in Chinamobileltd AN Lianbao WF Firmware-1 1.0.1
China Mobile An Lianbao WF-1 router v1.0.1 is affected by an OS command injection vulnerability in the web interface /api/ZRUsb/pop_usb_device component.
network
low complexity
chinamobileltd CWE-78
critical
9.8
2019-07-19 CVE-2019-1010136 Missing Authentication for Critical Function vulnerability in Chinamobileltd Gpn2.4P21-C-Cn Firmware W2001En00
ChinaMobile GPN2.4P21-C-CN W2001EN-00 is affected by: Incorrect Access Control - Unauthenticated Remote Reboot.
network
low complexity
chinamobileltd CWE-306
7.5
2019-03-21 CVE-2019-6282 Cross-Site Request Forgery (CSRF) vulnerability in Chinamobileltd Gpn2.4P21-C-Cn Firmware W2001En00
ChinaMobile PLC Wireless Router GPN2.4P21-C-CN devices with firmware W2001EN-00 have CSRF via the cgi-bin/webproc?getpage=html/index.html subpage=wlsecurity URI, allowing an Attacker to change the Wireless Security Password.
network
low complexity
chinamobileltd CWE-352
8.8
2019-03-21 CVE-2019-6279 Unspecified vulnerability in Chinamobileltd Gpn2.4P21-C-Cn Firmware W2001En00
ChinaMobile PLC Wireless Router GPN2.4P21-C-CN devices with firmware W2001EN-00 have an Incorrect Access Control vulnerability via the cgi-bin/webproc?getpage=html/index.html subpage=wlsecurity URI, allowing an Attacker to change the Wireless Security Password.
network
low complexity
chinamobileltd
8.8