Vulnerabilities > Stengg > Vpncrypt M10 Firmware > 2.6.5

DATE CVE VULNERABILITY TITLE RISK
2020-08-12 CVE-2020-12107 OS Command Injection vulnerability in Stengg Vpncrypt M10 Firmware 2.6.5
The Web portal of the WiFi module of VPNCrypt M10 2.6.5 allows command injection via a text field, which allow full control over this module's Operating System.
network
low complexity
stengg CWE-78
7.5
2020-08-12 CVE-2020-12106 Improper Input Validation vulnerability in Stengg Vpncrypt M10 Firmware 2.6.5
The Web portal of the WiFi module of VPNCrypt M10 2.6.5 allows unauthenticated users to send HTTP POST request to several critical Administrative functions such as, changing credentials of the Administrator account or connect the product to a rogue access point.
network
low complexity
stengg CWE-20
7.5