Vulnerabilities > Corega > Medium

DATE CVE VULNERABILITY TITLE RISK
2018-03-09 CVE-2017-10854 Missing Authentication for Critical Function vulnerability in Corega Cg-Wgr 1200 Firmware
Corega CG-WGR1200 firmware 2.20 and earlier allows an attacker to bypass authentication and change the login password via unspecified vectors.
low complexity
corega CWE-306
5.8
2017-06-09 CVE-2016-7811 Improper Access Control vulnerability in Corega Cg-Wlr300Nx Firmware
Corega CG-WLR300NX firmware Ver.
low complexity
corega CWE-284
5.8
2017-06-09 CVE-2016-7809 Cross-Site Request Forgery (CSRF) vulnerability in Corega Cg-Wlr300Nx Firmware
Cross-site request forgery (CSRF) vulnerability in Corega CG-WLR300NX firmware Ver.
network
corega CWE-352
6.8
2017-06-09 CVE-2016-7808 Cross-site Scripting vulnerability in Corega Cg-Wlbaragm Firmware and Cg-Wlbargnl Firmware
Cross-site scripting vulnerability in Corega CG-WLBARGMH and CG-WLBARGNL allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
network
corega CWE-79
4.3
2016-06-25 CVE-2016-4824 7PK - Security Features vulnerability in Corega Cg-Wlr300Gnv-W Firmware and Cg-Wlr300Gnv Firmware
The Wi-Fi Protected Setup (WPS) implementation on Corega CG-WLR300GNV and CG-WLR300GNV-W devices does not restrict the number of PIN authentication attempts, which makes it easier for remote attackers to obtain network access via a brute-force attack.
network
low complexity
corega CWE-254
5.0
2016-03-03 CVE-2016-1158 Cross-Site Request Forgery (CSRF) vulnerability in Corega Cg-Wlbargmh Firmware and Cg-Wlbargnl Firmware
Cross-site request forgery (CSRF) vulnerability on Corega CG-WLBARGMH and CG-WLBARGNL devices allows remote attackers to hijack the authentication of administrators for requests that perform administrative functions.
network
high complexity
corega CWE-352
5.1
2015-12-30 CVE-2015-7794 Improper Input Validation vulnerability in Corega Cg-Wlncm4G Firmware
Corega CG-WLNCM4G devices provide an open DNS resolver, which allows remote attackers to cause a denial of service (traffic amplification) via crafted queries.
network
low complexity
corega CWE-20
5.0
2015-12-30 CVE-2015-7793 Code vulnerability in Corega Cg-Wlbaragm Firmware
Corega CG-WLBARAGM devices provide an open proxy service, which allows remote attackers to trigger outbound network traffic via unspecified vectors.
network
low complexity
corega CWE-17
5.0