Vulnerabilities > Hytec

DATE CVE VULNERABILITY TITLE RISK
2022-08-29 CVE-2022-36553 Command Injection vulnerability in Hytec Hwl-2511-Ss Firmware 1.05
Hytec Inter HWL-2511-SS v1.05 and below was discovered to contain a command injection vulnerability via the component /www/cgi-bin/popen.cgi.
network
low complexity
hytec CWE-77
critical
9.8
2022-08-29 CVE-2022-36554 Command Injection vulnerability in Hytec Hwl-2511-Ss Firmware 1.05
A command injection vulnerability in the CLI (Command Line Interface) implementation of Hytec Inter HWL-2511-SS v1.05 and below allows attackers to execute arbitrary commands with root privileges.
network
low complexity
hytec CWE-77
critical
9.8
2022-08-29 CVE-2022-36555 Inadequate Encryption Strength vulnerability in Hytec Hwl-2511-Ss Firmware 1.05
Hytec Inter HWL-2511-SS v1.05 and below implements a SHA512crypt hash for the root account which can be easily cracked via a brute-force attack.
network
low complexity
hytec CWE-326
critical
9.8