Vulnerabilities > Furunosystems

DATE CVE VULNERABILITY TITLE RISK
2023-10-03 CVE-2023-39222 OS Command Injection vulnerability in Furunosystems products
OS command injection vulnerability in FURUNO SYSTEMS wireless LAN access point devices allows an authenticated user to execute an arbitrary OS command that is not intended to be executed from the web interface by sending a specially crafted request.
network
low complexity
furunosystems CWE-78
8.8
2023-10-03 CVE-2023-39429 Cross-site Scripting vulnerability in Furunosystems products
Cross-site scripting vulnerability in FURUNO SYSTEMS wireless LAN access point devices allows an authenticated user to inject an arbitrary script via a crafted configuration.
network
low complexity
furunosystems CWE-79
5.4
2023-10-03 CVE-2023-41086 Cross-Site Request Forgery (CSRF) vulnerability in Furunosystems products
Cross-site request forgery (CSRF) vulnerability exists in FURUNO SYSTEMS wireless LAN access point devices.
network
low complexity
furunosystems CWE-352
8.8
2023-10-03 CVE-2023-42771 Improper Authentication vulnerability in Furunosystems Acera 1310 Firmware and Acera 1320 Firmware
Authentication bypass vulnerability in ACERA 1320 firmware ver.01.26 and earlier, and ACERA 1310 firmware ver.01.26 and earlier allows a network-adjacent unauthenticated attacker who can access the affected product to download configuration files and/or log files, and upload configuration files and/or firmware.
low complexity
furunosystems CWE-287
8.8
2023-10-03 CVE-2023-43627 Path Traversal vulnerability in Furunosystems Acera 1310 Firmware and Acera 1320 Firmware
Path traversal vulnerability in ACERA 1320 firmware ver.01.26 and earlier, and ACERA 1310 firmware ver.01.26 and earlier allows a network-adjacent authenticated attacker to alter critical information such as system files by sending a specially crafted request.
low complexity
furunosystems CWE-22
5.7