Vulnerabilities > Furunosystems
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2023-10-03 | CVE-2023-39222 | OS Command Injection vulnerability in Furunosystems products OS command injection vulnerability in FURUNO SYSTEMS wireless LAN access point devices allows an authenticated user to execute an arbitrary OS command that is not intended to be executed from the web interface by sending a specially crafted request. | 8.8 |
2023-10-03 | CVE-2023-39429 | Cross-site Scripting vulnerability in Furunosystems products Cross-site scripting vulnerability in FURUNO SYSTEMS wireless LAN access point devices allows an authenticated user to inject an arbitrary script via a crafted configuration. | 5.4 |
2023-10-03 | CVE-2023-41086 | Cross-Site Request Forgery (CSRF) vulnerability in Furunosystems products Cross-site request forgery (CSRF) vulnerability exists in FURUNO SYSTEMS wireless LAN access point devices. | 8.8 |
2023-10-03 | CVE-2023-42771 | Improper Authentication vulnerability in Furunosystems Acera 1310 Firmware and Acera 1320 Firmware Authentication bypass vulnerability in ACERA 1320 firmware ver.01.26 and earlier, and ACERA 1310 firmware ver.01.26 and earlier allows a network-adjacent unauthenticated attacker who can access the affected product to download configuration files and/or log files, and upload configuration files and/or firmware. | 8.8 |
2023-10-03 | CVE-2023-43627 | Path Traversal vulnerability in Furunosystems Acera 1310 Firmware and Acera 1320 Firmware Path traversal vulnerability in ACERA 1320 firmware ver.01.26 and earlier, and ACERA 1310 firmware ver.01.26 and earlier allows a network-adjacent authenticated attacker to alter critical information such as system files by sending a specially crafted request. | 5.7 |