Vulnerabilities > Swisscom > Centro Grande Firmware > 6.12.02

DATE CVE VULNERABILITY TITLE RISK
2020-03-16 CVE-2019-19942 Improper Input Validation vulnerability in Swisscom Centro Business and Centro Grande Firmware
Missing output sanitation in Swisscom Centro Grande Centro Grande before 6.16.12, Centro Business 1.0 (ADB) before 7.10.18, and Centro Business 2.0 before 8.02.04 allows a remote attacker to perform DNS spoofing against the web interface via crafted hostnames in DHCP requests.
network
low complexity
swisscom CWE-20
5.0
2020-03-16 CVE-2019-19941 Cross-site Scripting vulnerability in Swisscom Centro Grande Firmware 6.12.02/6.14.00
Missing hostname validation in Swisscom Centro Grande before 6.16.12 allows a remote attacker to inject its local IP address as a domain entry in the DNS service of the router via crafted hostnames in DHCP requests, causing XSS.
network
swisscom CWE-79
3.5
2020-03-16 CVE-2019-19940 OS Command Injection vulnerability in Swisscom Centro Grande Firmware 6.12.02/6.14.00
Incorrect input sanitation in text-oriented user interfaces (telnet, ssh) in Swisscom Centro Grande before 6.16.12 allows remote authenticated users to execute arbitrary commands via command injection.
network
low complexity
swisscom CWE-78
critical
9.0
2015-05-20 CVE-2015-1188 Unspecified vulnerability in Swisscom Centro Grande Firmware 6.12.02
The certificate verification functions in the HNDS service in Swisscom Centro Grande (ADB) DSL routers with firmware before 6.14.00 allows remote attackers to access the management functions via unknown vectors.
network
low complexity
swisscom
7.5