Vulnerabilities > Iball

DATE CVE VULNERABILITY TITLE RISK
2021-12-30 CVE-2020-29292 Cross-Site Request Forgery (CSRF) vulnerability in Iball Wrd12En Firmware 1.0.0
iBall WRD12EN 1.0.0 devices allow cross-site request forgery (CSRF) attacks as demonstrated by enabling DNS settings or modifying the range for IP addresses.
network
low complexity
iball CWE-352
6.5
2020-06-29 CVE-2020-15043 Cross-Site Request Forgery (CSRF) vulnerability in Iball Wrb303N Firmware
iBall WRB303N devices allow CSRF attacks, as demonstrated by enabling remote management, enabling DHCP, or modifying the subnet range for IP addresses.
network
low complexity
iball CWE-352
6.5
2019-05-28 CVE-2018-20008 Incorrect Permission Assignment for Critical Resource vulnerability in Iball Ib-Wrb302N Firmware Ibwrb302N20122017
iBall Baton iB-WRB302N20122017 devices have improper access control over the UART interface, allowing physical attackers to discover Wi-Fi credentials (plain text) and the web-console password (base64) via the debugging console.
low complexity
iball CWE-732
6.8
2018-01-30 CVE-2018-6355 Cross-site Scripting vulnerability in Iball Ib-Wrb302N Firmware 1.0.1Sep82017
/goform/setLang on iBall 300M devices with "iB-WRB302N_1.0.1-Sep 8 2017" firmware has Unauthenticated Stored Cross Site Scripting via the lang parameter.
network
low complexity
iball CWE-79
6.1
2018-01-29 CVE-2018-6388 OS Command Injection vulnerability in Iball Ib-Wra150N Firmware 1.2.6
iBall iB-WRA150N 1.2.6 build 110401 Rel.47776n devices allow remote authenticated users to execute arbitrary OS commands via shell metacharacters in the ping test arguments on the Diagnostics page.
network
low complexity
iball CWE-78
8.8
2018-01-29 CVE-2018-6387 Use of Hard-coded Credentials vulnerability in Iball Ib-Wra150N Firmware 1.2.6
iBall iB-WRA150N 1.2.6 build 110401 Rel.47776n devices have a hardcoded password of admin for the admin account, a hardcoded password of support for the support account, and a hardcoded password of user for the user account.
network
low complexity
iball CWE-798
critical
9.8
2017-11-13 CVE-2017-11169 Unspecified vulnerability in Iball Ib-Wra300N3Gt Firmware 1.1.1
Privilege Escalation on iBall iB-WRA300N3GT iB-WRA300N3GT_1.1.1 devices allows remote authenticated users to obtain root privileges by leveraging a guest/user/normal account to submit a modified privilege parameter to /form2userconfig.cgi.
network
low complexity
iball
8.8
2017-09-17 CVE-2017-14244 Forced Browsing vulnerability in Iball Ib-Wra150N Firmware Fwiblr7011A1.0.2
An authentication bypass vulnerability on iBall Baton ADSL2+ Home Router FW_iB-LR7011A_1.0.2 devices potentially allows attackers to directly access administrative router settings by crafting URLs with a .cgi extension, as demonstrated by /info.cgi and /password.cgi.
network
low complexity
iball CWE-425
critical
9.8
2017-03-09 CVE-2017-6558 Use of Hard-coded Credentials vulnerability in Iball Ib-Wra150N Firmware 1.2.6
iball Baton 150M iB-WRA150N v1 00000001 1.2.6 build 110401 Rel.47776n devices are prone to an authentication bypass vulnerability that allows remote attackers to view and modify administrative router settings by reading the HTML source code of the password.cgi file.
network
low complexity
iball CWE-798
critical
9.8