Vulnerabilities > Critical

DATE CVE VULNERABILITY TITLE RISK
2024-02-06 CVE-2024-22853 Use of Hard-coded Credentials vulnerability in Dlink Go-Rt-Ac750 Firmware 101B03
D-LINK Go-RT-AC750 GORTAC750_A1_FW_v101b03 has a hardcoded password for the Alphanetworks account, which allows remote attackers to obtain root access via a telnet session.
network
low complexity
dlink CWE-798
critical
9.8
2024-02-06 CVE-2023-46359 OS Command Injection vulnerability in Hardy-Barth Cph2 Echarge Firmware
An OS command injection vulnerability in Hardy Barth cPH2 eCharge Ladestation v1.87.0 and earlier, may allow an unauthenticated remote attacker to execute arbitrary commands on the system via a specifically crafted arguments passed to the connectivity check feature.
network
low complexity
hardy-barth CWE-78
critical
9.8
2024-02-06 CVE-2023-6229 Out-of-bounds Write vulnerability in Canon products
Buffer overflow in CPCA PDL Resource Download process of Office Multifunction Printers and Laser Printers(*) which may allow an attacker on the network segment to trigger the affected product being unresponsive or to execute arbitrary code.*: Satera LBP670C Series/Satera MF750C Series firmware v03.07 and earlier sold in Japan.
network
low complexity
canon CWE-787
critical
9.8
2024-02-06 CVE-2023-6230 Out-of-bounds Write vulnerability in Canon products
Buffer overflow in the Address Book password process in authentication of Mobile Device Function of Office Multifunction Printers and Laser Printers(*) which may allow an attacker on the network segment to trigger the affected product being unresponsive or to execute arbitrary code.*: Satera LBP670C Series/Satera MF750C Series firmware v03.07 and earlier sold in Japan.
network
low complexity
canon CWE-787
critical
9.8
2024-02-06 CVE-2023-6231 Out-of-bounds Write vulnerability in Canon products
Buffer overflow in WSD probe request process of Office Multifunction Printers and Laser Printers(*) which may allow an attacker on the network segment to trigger the affected product being unresponsive or to execute arbitrary code.*: Satera LBP670C Series/Satera MF750C Series firmware v03.07 and earlier sold in Japan.
network
low complexity
canon CWE-787
critical
9.8
2024-02-06 CVE-2023-6232 Out-of-bounds Write vulnerability in Canon products
Buffer overflow in the Address Book username process in authentication of Mobile Device Function of Office Multifunction Printers and Laser Printers(*) which may allow an attacker on the network segment to trigger the affected product being unresponsive or to execute arbitrary code.*: Satera LBP670C Series/Satera MF750C Series firmware v03.07 and earlier sold in Japan.
network
low complexity
canon CWE-787
critical
9.8
2024-02-06 CVE-2023-6233 Out-of-bounds Write vulnerability in Canon products
Buffer overflow in SLP attribute request process of Office Multifunction Printers and Laser Printers(*) which may allow an attacker on the network segment to trigger the affected product being unresponsive or to execute arbitrary code.*: Satera LBP670C Series/Satera MF750C Series firmware v03.07 and earlier sold in Japan.
network
low complexity
canon CWE-787
critical
9.8
2024-02-06 CVE-2023-6234 Out-of-bounds Write vulnerability in Canon products
Buffer overflow in CPCA Color LUT Resource Download process of Office Multifunction Printers and Laser Printers(*) which may allow an attacker on the network segment to trigger the affected product being unresponsive or to execute arbitrary code.*: Satera LBP670C Series/Satera MF750C Series firmware v03.07 and earlier sold in Japan.
network
low complexity
canon CWE-787
critical
9.8
2024-02-06 CVE-2024-0244 Out-of-bounds Write vulnerability in Canon products
Buffer overflow in CPCA PCFAX number process of Office Multifunction Printers and Laser Printers(*) which may allow an attacker on the network segment to trigger the affected product being unresponsive or to execute arbitrary code.*:Satera MF750C Series firmware v03.07 and earlier sold in Japan.
network
low complexity
canon CWE-787
critical
9.8
2024-02-06 CVE-2024-24112 SQL Injection vulnerability in Exrick Xmall 1.1
xmall v1.1 was discovered to contain a SQL injection vulnerability via the orderDir parameter.
network
low complexity
exrick CWE-89
critical
9.8