Vulnerabilities > Hughes > Hn7000S Firmware

DATE CVE VULNERABILITY TITLE RISK
2023-01-26 CVE-2023-22971 Cross-site Scripting vulnerability in Hughes products
Cross Site Scripting (XSS) vulnerability in Hughes Network Systems Router Terminal for HX200 v8.3.1.14, HX90 v6.11.0.5, HX50L v6.10.0.18, HN9460 v8.2.0.48, and HN7000S v6.9.0.37, allows unauthenticated attackers to misuse frames, include JS/HTML code and steal sensitive information from legitimate users of the application.
network
low complexity
hughes CWE-79
6.1
2018-07-13 CVE-2016-9497 Improper Authentication vulnerability in Hughes products
Hughes high-performance broadband satellite modems, models HN7740S DW7000 HN7000S/SM, is vulnerable to an authentication bypass using an alternate path or channel.
low complexity
hughes CWE-287
8.3
2018-07-13 CVE-2016-9496 Missing Authentication for Critical Function vulnerability in Hughes products
Hughes high-performance broadband satellite modems, models HN7740S DW7000 HN7000S/SM, lacks authentication.
low complexity
hughes CWE-306
6.1
2018-07-13 CVE-2016-9495 Use of Hard-coded Credentials vulnerability in Hughes products
Hughes high-performance broadband satellite modems, models HN7740S DW7000 HN7000S/SM, uses hard coded credentials.
low complexity
hughes CWE-798
5.8
2018-07-13 CVE-2016-9494 Improper Input Validation vulnerability in Hughes products
Hughes high-performance broadband satellite modems, models HN7740S DW7000 HN7000S/SM, are potentially vulnerable to improper input validation.
low complexity
hughes CWE-20
3.3