Vulnerabilities > Hootoo

DATE CVE VULNERABILITY TITLE RISK
2019-06-11 CVE-2018-20841 OS Command Injection vulnerability in Hootoo Tripmate Titan Ht-Tm05 Firmware 2.000.022/2.000.082
HooToo TripMate Titan HT-TM05 and HT-05 routers with firmware 2.000.022 and 2.000.082 allow remote command execution via shell metacharacters in the mac parameter of a protocol.csp?function=set&fname=security&opt=mac_table request.
network
low complexity
hootoo CWE-78
critical
9.8
2017-05-17 CVE-2017-9026 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Hootoo Trip Mate 6 Firmware 2.000.030
Stack buffer overflow in vshttpd (aka ioos) in HooToo Trip Mate 6 (TM6) firmware 2.000.030 and earlier allows remote unauthenticated attackers to control the program counter via a specially crafted fname parameter of a GET request.
network
low complexity
hootoo CWE-119
critical
9.8
2017-05-17 CVE-2017-9025 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Hootoo Trip Mate 6 Firmware 2.000.030
Heap buffer overflow in vshttpd (aka ioos) in HooToo Trip Mate 6 (TM6) firmware 2.000.030 and earlier allows remote unauthenticated attackers to control the program counter via a specially crafted HTTP Cookie header.
network
low complexity
hootoo CWE-119
6.5