Vulnerabilities > Mimosa

DATE CVE VULNERABILITY TITLE RISK
2021-07-20 CVE-2020-25205 Cross-site Scripting vulnerability in Mimosa B5 Firmware, B5C Firmware and C5C Firmware
The web console for Mimosa B5, B5c, and C5x firmware through 2.8.0.2 is vulnerable to stored XSS in the set_banner() function of /var/www/core/controller/index.php.
network
low complexity
mimosa CWE-79
6.1
2021-07-20 CVE-2020-25206 OS Command Injection vulnerability in Mimosa B5 Firmware, B5C Firmware and C5C Firmware
The web console for Mimosa B5, B5c, and C5x firmware through 2.8.0.2 allows authenticated command injection in the Throughput, WANStats, PhyStats, and QosStats API classes.
network
low complexity
mimosa CWE-78
7.2
2017-05-21 CVE-2017-9136 Incorrect Permission Assignment for Critical Resource vulnerability in Mimosa Backhaul Radios and Client Radios
An issue was discovered on Mimosa Client Radios before 2.2.3.
network
low complexity
mimosa CWE-732
7.5
2017-05-21 CVE-2017-9135 Injection vulnerability in Mimosa Backhaul Radios and Client Radios
An issue was discovered on Mimosa Client Radios before 2.2.4 and Mimosa Backhaul Radios before 2.2.4.
network
low complexity
mimosa CWE-74
8.8
2017-05-21 CVE-2017-9134 Information Exposure vulnerability in Mimosa Backhaul Radios and Client Radios
An information-leakage issue was discovered on Mimosa Client Radios before 2.2.3 and Mimosa Backhaul Radios before 2.2.3.
network
low complexity
mimosa CWE-200
7.5
2017-05-21 CVE-2017-9133 Injection vulnerability in Mimosa Backhaul Radios and Client Radios
An issue was discovered on Mimosa Client Radios before 2.2.3 and Mimosa Backhaul Radios before 2.2.3.
network
low complexity
mimosa CWE-74
8.8
2017-05-21 CVE-2017-9132 Use of Hard-coded Credentials vulnerability in Mimosa Backhaul Radios and Client Radios
A hard-coded credentials issue was discovered on Mimosa Client Radios before 2.2.3, Mimosa Backhaul Radios before 2.2.3, and Mimosa Access Points before 2.2.3.
network
low complexity
mimosa CWE-798
7.5
2017-05-21 CVE-2017-9131 Improper Input Validation vulnerability in Mimosa Backhaul Radios and Client Radios
An issue was discovered on Mimosa Client Radios before 2.2.3 and Mimosa Backhaul Radios before 2.2.3.
network
low complexity
mimosa CWE-20
7.5