Vulnerabilities > Meinbwa

DATE CVE VULNERABILITY TITLE RISK
2020-03-09 CVE-2020-10250 OS Command Injection vulnerability in Meinbwa Direx-Pro Firmware 1.2181
BWA DiREX-Pro 1.2181 devices allow remote attackers to execute arbitrary OS commands via shell metacharacters in the PKG parameter to uninstall.php3.
network
low complexity
meinbwa CWE-78
critical
9.8
2020-03-09 CVE-2020-10249 Unspecified vulnerability in Meinbwa Direx-Pro Firmware 1.2181
BWA DiREX-Pro 1.2181 devices allow full path disclosure via an invalid name array parameter to val_soft.php3.
network
low complexity
meinbwa
5.3
2020-03-09 CVE-2020-10248 Forced Browsing vulnerability in Meinbwa Direx-Pro Firmware 1.2181
BWA DiREX-Pro 1.2181 devices allow remote attackers to discover passwords via a direct request to val_users.php3.
network
low complexity
meinbwa CWE-425
7.5