Vulnerabilities > Iodata > Critical

DATE CVE VULNERABILITY TITLE RISK
2023-04-14 CVE-2023-29805 OS Command Injection vulnerability in Iodata Wfs-Sr03K Firmware and Wfs-Sr03W Firmware
WFS-SR03 v1.0.3 was discovered to contain a command injection vulnerability via the pro_stor_canceltrans_handler_part_19 function.
network
low complexity
iodata CWE-78
critical
9.8
2017-06-09 CVE-2016-7806 OS Command Injection vulnerability in Iodata Wfs-Sr01 Firmware 1.10
I-O DATA DEVICE WFS-SR01 firmware version 1.10 and earlier allow remote attackers to execute arbitrary OS commands via unspecified vectors.
network
low complexity
iodata CWE-78
critical
9.8
2017-04-28 CVE-2017-2142 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Iodata Wn-G300R3 Firmware 1.01/1.03
Buffer overflow in WN-G300R3 firmware Ver.1.03 and earlier allows remote attackers to execute arbitrary OS commands via unspecified vectors.
network
low complexity
iodata CWE-119
critical
9.8