Vulnerabilities > Corega > High

DATE CVE VULNERABILITY TITLE RISK
2018-03-09 CVE-2017-10854 Missing Authentication for Critical Function vulnerability in Corega Cg-Wgr 1200 Firmware 2.20
Corega CG-WGR1200 firmware 2.20 and earlier allows an attacker to bypass authentication and change the login password via unspecified vectors.
low complexity
corega CWE-306
8.8
2018-03-09 CVE-2017-10853 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Corega Cg-Wgr 1200 Firmware 2.20
Buffer overflow in Corega CG-WGR1200 firmware 2.20 and earlier allows an attacker to execute arbitrary commands via unspecified vectors.
low complexity
corega CWE-119
8.8
2018-03-09 CVE-2017-10852 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Corega Cg-Wgr 1200 Firmware 2.20
Buffer overflow in Corega CG-WGR1200 firmware 2.20 and earlier allows an attacker to execute arbitrary code via unspecified vectors.
low complexity
corega CWE-119
8.8
2017-06-09 CVE-2016-7811 Improper Access Control vulnerability in Corega Cg-Wlr300Nx Firmware 1.20
Corega CG-WLR300NX firmware Ver.
low complexity
corega CWE-284
8.8
2017-06-09 CVE-2016-7809 Cross-Site Request Forgery (CSRF) vulnerability in Corega Cg-Wlr300Nx Firmware 1.20
Cross-site request forgery (CSRF) vulnerability in Corega CG-WLR300NX firmware Ver.
network
low complexity
corega CWE-352
8.8
2016-06-25 CVE-2016-4823 Unspecified vulnerability in Corega Cg-Wlbaragm Firmware
Corega CG-WLBARAGM devices allow remote attackers to cause a denial of service (reboot) via unspecified vectors.
network
low complexity
corega
7.5
2016-06-25 CVE-2016-4822 Command Injection vulnerability in Corega Cg-Wlbargl Firmware
Corega CG-WLBARGL devices allow remote authenticated users to execute arbitrary commands via unspecified vectors.
low complexity
corega CWE-77
8.0
2016-03-03 CVE-2016-1158 Cross-Site Request Forgery (CSRF) vulnerability in Corega Cg-Wlbargmh Firmware and Cg-Wlbargnl Firmware
Cross-site request forgery (CSRF) vulnerability on Corega CG-WLBARGMH and CG-WLBARGNL devices allows remote attackers to hijack the authentication of administrators for requests that perform administrative functions.
network
low complexity
corega CWE-352
8.8