Vulnerabilities > NEC > High

DATE CVE VULNERABILITY TITLE RISK
2019-01-09 CVE-2018-0628 OS Command Injection vulnerability in NEC Aterm Wg1200Hp Firmware 1.0.31/1.0.8
Aterm WG1200HP firmware Ver1.0.31 and earlier allows attacker with administrator rights to execute arbitrary OS commands via HTTP request and response.
network
low complexity
nec CWE-78
7.2
2019-01-09 CVE-2018-0627 OS Command Injection vulnerability in NEC Aterm Wg1200Hp Firmware 1.0.31/1.0.8
Aterm WG1200HP firmware Ver1.0.31 and earlier allows attacker with administrator rights to execute arbitrary OS commands via targetAPSsid parameter.
network
low complexity
nec CWE-78
7.2
2019-01-09 CVE-2018-0626 OS Command Injection vulnerability in NEC Aterm Wg1200Hp Firmware 1.0.31/1.0.8
Aterm WG1200HP firmware Ver1.0.31 and earlier allows attacker with administrator rights to execute arbitrary OS commands via sysCmd in formWsc parameter.
network
low complexity
nec CWE-78
7.2
2019-01-09 CVE-2018-0625 OS Command Injection vulnerability in NEC Aterm Wg1200Hp Firmware 1.0.31/1.0.8
Aterm WG1200HP firmware Ver1.0.31 and earlier allows attacker with administrator rights to execute arbitrary OS commands via formSysCmd parameter.
network
low complexity
nec CWE-78
7.2
2016-01-30 CVE-2016-1145 Path Traversal vulnerability in NEC Expresscluster X 3.3
Directory traversal vulnerability in WebManager in NEC EXPRESSCLUSTER X through 3.3 11.31 on Windows and through 3.3 3.3.1-1 on Linux and Solaris allows remote attackers to read arbitrary files via unspecified vectors.
network
low complexity
nec CWE-22
7.5