Vulnerabilities > Furuno

DATE CVE VULNERABILITY TITLE RISK
2018-09-10 CVE-2018-16705 Information Exposure vulnerability in Furuno Felcom 250 Firmware and Felcom 500 Firmware
FURUNO FELCOM 250 and 500 devices allow unauthenticated access to the xml/permission.xml file containing all of the system's usernames and passwords.
network
low complexity
furuno CWE-200
critical
9.8
2018-09-10 CVE-2018-16591 Missing Authorization vulnerability in Furuno Felcom 250 Firmware and Felcom 500 Firmware
FURUNO FELCOM 250 and 500 devices allow unauthenticated users to change the password for the Admin, Log and Service accounts, as well as the password for the protected "SMS" panel via /cgi-bin/sm_changepassword.cgi and /cgi-bin/sm_sms_changepasswd.cgi.
network
low complexity
furuno CWE-862
critical
9.8
2018-09-06 CVE-2018-16590 Improper Authentication vulnerability in Furuno Felcom 250 Firmware and Felcom 500 Firmware
FURUNO FELCOM 250 and 500 devices use only client-side JavaScript in login.js for authentication.
network
low complexity
furuno CWE-287
critical
9.8