Vulnerabilities > Iodata > High

DATE CVE VULNERABILITY TITLE RISK
2017-06-09 CVE-2016-7820 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Iodata Ts-Wrla Firmware and Ts-Wrlp Firmware
Buffer overflow in I-O DATA DEVICE TS-WRLP firmware version 1.01.02 and earlier and TS-WRLA firmware version 1.01.02 and earlier allows an attacker with administrator rights to cause a denial-of-service (DoS) or execute arbitrary code via unspecified vectors.
network
low complexity
iodata CWE-119
7.2
2017-06-09 CVE-2016-7819 OS Command Injection vulnerability in Iodata Ts-Wrla Firmware and Ts-Wrlp Firmware
I-O DATA DEVICE TS-WRLP firmware version 1.01.02 and earlier and TS-WRLA firmware version 1.01.02 and earlier allows an attacker with administrator rights to execute arbitrary OS commands via unspecified vectors.
network
low complexity
iodata CWE-78
7.2
2017-06-09 CVE-2016-7814 Information Exposure vulnerability in Iodata Ts-Wrla Firmware and Ts-Wrlp Firmware
I-O DATA DEVICE TS-WRLP firmware version 1.00.01 and earlier and TS-WRLA firmware version 1.00.01 and earlier allow remote attackers to obtain authentication credentials via unspecified vectors.
network
low complexity
iodata CWE-200
7.5
2017-06-09 CVE-2016-7807 Improper Access Control vulnerability in Iodata Wfs-Sr01 Firmware 1.10
I-O DATA DEVICE WFS-SR01 firmware version 1.10 and earlier allow remote attackers to bypass access restriction to access data on storage devices inserted into the product via unspecified vectors.
network
low complexity
iodata CWE-284
7.5
2017-04-28 CVE-2017-2141 OS Command Injection vulnerability in Iodata Wn-G300R3 Firmware 1.01/1.03
WN-G300R3 firmware 1.03 and earlier allows attackers with administrator rights to execute arbitrary OS commands via unspecified vectors.
network
low complexity
iodata CWE-78
7.2
2017-04-28 CVE-2017-2113 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Iodata products
Buffer overflow in TS-WPTCAM firmware version 1.18 and earlier, TS-WPTCAM2 firmware version 1.00, TS-WLCE firmware version 1.18 and earlier, TS-WLC2 firmware version 1.18 and earlier, TS-WRLC firmware version 1.17 and earlier, TS-PTCAM firmware version 1.18 and earlier, TS-PTCAM/POE firmware version 1.18 and earlier allows remote attackers to execute arbitrary OS commands via unspecified vectors.
low complexity
iodata CWE-119
8.8
2017-04-28 CVE-2017-2112 OS Command Injection vulnerability in Iodata products
TS-WPTCAM firmware version 1.18 and earlier, TS-WPTCAM2 firmware version 1.00, TS-WLCE firmware version 1.18 and earlier, TS-WLC2 firmware version 1.18 and earlier, TS-WRLC firmware version 1.17 and earlier, TS-PTCAM firmware version 1.18 and earlier, TS-PTCAM/POE firmware version 1.18 and earlier allows remote attackers to execute arbitrary OS commands via unspecified vectors.
low complexity
iodata CWE-78
8.8
2016-09-24 CVE-2016-4845 Cross-Site Request Forgery (CSRF) vulnerability in Iodata products
Cross-site request forgery (CSRF) vulnerability on I-O DATA DEVICE HVL-A2.0, HVL-A3.0, HVL-A4.0, HVL-AT1.0S, HVL-AT2.0, HVL-AT3.0, HVL-AT4.0, HVL-AT2.0A, HVL-AT3.0A, and HVL-AT4.0A devices with firmware before 2.04 allows remote attackers to hijack the authentication of arbitrary users for requests that delete content.
network
low complexity
iodata CWE-352
8.8
2016-06-19 CVE-2016-4820 Cross-Site Request Forgery (CSRF) vulnerability in Iodata Etx-R Firmware
Cross-site request forgery (CSRF) vulnerability on I-O DATA DEVICE ETX-R devices allows remote attackers to hijack the authentication of arbitrary users.
network
low complexity
iodata CWE-352
8.8