Note:
This project will be discontinued after December 13, 2021. [more]
Product:
Acera_1320_firmware
(Furunosystems)Repositories |
Unknown: This might be proprietary software. |
#Vulnerabilities | 3 |
Date | Id | Summary | Products | Score | Patch | Annotated |
---|---|---|---|---|---|---|
2023-10-03 | CVE-2023-39222 | OS command injection vulnerability in FURUNO SYSTEMS wireless LAN access point devices allows an authenticated user to execute an arbitrary OS command that is not intended to be executed from the web interface by sending a specially crafted request. Affected products and versions are as follows: ACERA 1320 firmware ver.01.26 and earlier, ACERA 1310 firmware ver.01.26 and earlier, ACERA 1210 firmware ver.02.36 and earlier, ACERA 1150i firmware ver.01.35 and earlier, ACERA 1150w firmware... | Acera_1010_firmware, Acera_1020_firmware, Acera_1110_firmware, Acera_1150i_firmware, Acera_1150w_firmware, Acera_1210_firmware, Acera_1310_firmware, Acera_1320_firmware, Acera_800st_firmware, Acera_810_firmware, Acera_850f_firmware, Acera_850m_firmware, Acera_900_firmware, Acera_950_firmware | 8.8 | ||
2023-10-03 | CVE-2023-42771 | Authentication bypass vulnerability in ACERA 1320 firmware ver.01.26 and earlier, and ACERA 1310 firmware ver.01.26 and earlier allows a network-adjacent unauthenticated attacker who can access the affected product to download configuration files and/or log files, and upload configuration files and/or firmware. They are affected when running in ST(Standalone) mode. | Acera_1310_firmware, Acera_1320_firmware | 8.8 | ||
2023-10-03 | CVE-2023-43627 | Path traversal vulnerability in ACERA 1320 firmware ver.01.26 and earlier, and ACERA 1310 firmware ver.01.26 and earlier allows a network-adjacent authenticated attacker to alter critical information such as system files by sending a specially crafted request. They are affected when running in ST(Standalone) mode. | Acera_1310_firmware, Acera_1320_firmware | 5.7 |