Vulnerabilities > Corega
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2018-03-09 | CVE-2017-10854 | Missing Authentication for Critical Function vulnerability in Corega Cg-Wgr 1200 Firmware 2.20 Corega CG-WGR1200 firmware 2.20 and earlier allows an attacker to bypass authentication and change the login password via unspecified vectors. | 8.8 |
2018-03-09 | CVE-2017-10853 | Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Corega Cg-Wgr 1200 Firmware 2.20 Buffer overflow in Corega CG-WGR1200 firmware 2.20 and earlier allows an attacker to execute arbitrary commands via unspecified vectors. | 8.8 |
2018-03-09 | CVE-2017-10852 | Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Corega Cg-Wgr 1200 Firmware 2.20 Buffer overflow in Corega CG-WGR1200 firmware 2.20 and earlier allows an attacker to execute arbitrary code via unspecified vectors. | 8.8 |
2017-09-15 | CVE-2017-10814 | Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Corega WLR 300 NM Firmware 1.90 Buffer overflow in CG-WLR300NM Firmware version 1.90 and earlier allows an attacker to execute arbitrary code via unspecified vectors. | 6.8 |
2017-09-15 | CVE-2017-10813 | OS Command Injection vulnerability in Corega WLR 300 NM Firmware 1.90 CG-WLR300NM Firmware version 1.90 and earlier allows an attacker to execute arbitrary OS commands via unspecified vectors. | 6.8 |
2017-06-09 | CVE-2016-7811 | Improper Access Control vulnerability in Corega Cg-Wlr300Nx Firmware 1.20 Corega CG-WLR300NX firmware Ver. | 8.8 |
2017-06-09 | CVE-2016-7810 | Cross-site Scripting vulnerability in Corega Cg-Wlr300Nx Firmware 1.20 Cross-site scripting vulnerability in Corega CG-WLR300NX firmware Ver. | 4.8 |
2017-06-09 | CVE-2016-7809 | Cross-Site Request Forgery (CSRF) vulnerability in Corega Cg-Wlr300Nx Firmware 1.20 Cross-site request forgery (CSRF) vulnerability in Corega CG-WLR300NX firmware Ver. | 8.8 |
2017-06-09 | CVE-2016-7808 | Cross-site Scripting vulnerability in Corega Cg-Wlbaragm Firmware and Cg-Wlbargnl Firmware Cross-site scripting vulnerability in Corega CG-WLBARGMH and CG-WLBARGNL allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | 6.1 |
2016-06-25 | CVE-2016-4824 | 7PK - Security Features vulnerability in Corega Cg-Wlr300Gnv-W Firmware and Cg-Wlr300Gnv Firmware The Wi-Fi Protected Setup (WPS) implementation on Corega CG-WLR300GNV and CG-WLR300GNV-W devices does not restrict the number of PIN authentication attempts, which makes it easier for remote attackers to obtain network access via a brute-force attack. | 5.3 |