Vulnerabilities > HOT

DATE CVE VULNERABILITY TITLE RISK
2013-12-30 CVE-2013-5220 Improper Input Validation vulnerability in HOT Hotbox Router and Hotbox Router Firmware
goform/login on the HOT HOTBOX router with software 2.1.11 allows remote attackers to cause a denial of service (device crash) via crafted HTTP POST data.
low complexity
hot CWE-20
6.1
2013-12-30 CVE-2013-5219 Path Traversal vulnerability in HOT Hotbox Router and Hotbox Router Firmware
Directory traversal vulnerability on the HOT HOTBOX router with software 2.1.11 allows remote attackers to read arbitrary files via a ..
low complexity
hot CWE-22
3.3
2013-12-30 CVE-2013-5218 Cross-Site Scripting vulnerability in HOT Hotbox Router and Hotbox Router Firmware
Cross-site scripting (XSS) vulnerability on the HOT HOTBOX router with software 2.1.11 allows remote attackers to inject arbitrary web script or HTML via a crafted DHCP Host Name option, which is not properly handled during rendering of the DHCP table in wlanAccess.asp.
2.9
2013-12-30 CVE-2013-5039 Cross-Site Request Forgery (CSRF) vulnerability in HOT Hotbox Router and Hotbox Router Firmware
Cross-site request forgery (CSRF) vulnerability in goform/wlanBasicSecurity on the HOT HOTBOX router with software 2.1.11 allows remote attackers to hijack the authentication of administrators for requests that change the WiFi Security field to Deactivated via the WifiSecurity parameter.
5.4
2013-12-30 CVE-2013-5038 Improper Authentication vulnerability in HOT Hotbox Router and Hotbox Router Firmware
The HOT HOTBOX router with software 2.1.11 allows remote attackers to bypass authentication by configuring a source IP address that had previously been used for an authenticated session.
low complexity
hot CWE-287
5.8
2013-12-30 CVE-2013-5037 Credentials Management vulnerability in HOT Hotbox Router and Hotbox Router Firmware
The HOT HOTBOX router with software 2.1.11 has a default WPS PIN of 12345670, which makes it easier for remote attackers to obtain the WPA or WPA2 pre-shared key via EAP messages.
low complexity
hot CWE-255
3.3