Vulnerabilities > Corega > Medium

DATE CVE VULNERABILITY TITLE RISK
2017-09-15 CVE-2017-10814 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Corega WLR 300 NM Firmware 1.90
Buffer overflow in CG-WLR300NM Firmware version 1.90 and earlier allows an attacker to execute arbitrary code via unspecified vectors.
low complexity
corega CWE-119
6.8
2017-09-15 CVE-2017-10813 OS Command Injection vulnerability in Corega WLR 300 NM Firmware 1.90
CG-WLR300NM Firmware version 1.90 and earlier allows an attacker to execute arbitrary OS commands via unspecified vectors.
low complexity
corega CWE-78
6.8
2017-06-09 CVE-2016-7810 Cross-site Scripting vulnerability in Corega Cg-Wlr300Nx Firmware 1.20
Cross-site scripting vulnerability in Corega CG-WLR300NX firmware Ver.
network
low complexity
corega CWE-79
4.8
2017-06-09 CVE-2016-7808 Cross-site Scripting vulnerability in Corega Cg-Wlbaragm Firmware and Cg-Wlbargnl Firmware
Cross-site scripting vulnerability in Corega CG-WLBARGMH and CG-WLBARGNL allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
network
low complexity
corega CWE-79
6.1
2016-06-25 CVE-2016-4824 7PK - Security Features vulnerability in Corega Cg-Wlr300Gnv-W Firmware and Cg-Wlr300Gnv Firmware
The Wi-Fi Protected Setup (WPS) implementation on Corega CG-WLR300GNV and CG-WLR300GNV-W devices does not restrict the number of PIN authentication attempts, which makes it easier for remote attackers to obtain network access via a brute-force attack.
network
low complexity
corega CWE-254
5.3
2015-12-30 CVE-2015-7794 Improper Input Validation vulnerability in Corega Cg-Wlncm4G Firmware
Corega CG-WLNCM4G devices provide an open DNS resolver, which allows remote attackers to cause a denial of service (traffic amplification) via crafted queries.
network
low complexity
corega CWE-20
5.8
2015-12-30 CVE-2015-7793 Code vulnerability in Corega Cg-Wlbaragm Firmware
Corega CG-WLBARAGM devices provide an open proxy service, which allows remote attackers to trigger outbound network traffic via unspecified vectors.
network
low complexity
corega CWE-17
5.8