Note:
This project will be discontinued after December 13, 2021. [more]
Product:
Ew9_firmware
(Ip\-Com)Repositories |
Unknown: This might be proprietary software. |
#Vulnerabilities | 5 |
Date | Id | Summary | Products | Score | Patch | Annotated |
---|---|---|---|---|---|---|
2022-10-27 | CVE-2022-43364 | An access control issue in the password reset page of IP-COM EW9 V15.11.0.14(9732) allows unauthenticated attackers to arbitrarily change the admin password. | Ew9_firmware | 7.5 | ||
2022-10-27 | CVE-2022-43365 | IP-COM EW9 V15.11.0.14(9732) was discovered to contain a buffer overflow in the formSetDebugCfg function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted string. | Ew9_firmware | 7.5 | ||
2022-10-27 | CVE-2022-43366 | IP-COM EW9 V15.11.0.14(9732) allows unauthenticated attackers to access sensitive information via the checkLoginUser, ate, telnet, version, setDebugCfg, and boot interfaces. | Ew9_firmware | 7.5 | ||
2022-10-27 | CVE-2022-43367 | IP-COM EW9 V15.11.0.14(9732) was discovered to contain a command injection vulnerability in the formSetDebugCfg function. | Ew9_firmware | 9.8 | ||
2022-12-13 | CVE-2022-45005 | IP-COM EW9 V15.11.0.14(9732) was discovered to contain a command injection vulnerability in the cmd_get_ping_output function. | Ew9_firmware | 9.8 |