CWE-494
209 CVEs • Abstraction: Base • Likelihood of Exploit: Medium
Download of Code Without Integrity Check
The product downloads source code or an executable from a remote location and executes the code without sufficiently verifying the origin and integrity of the code.
CVEs (209)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Synel 21Bioentry W2 Firmware Bioentry P2 FirmwareBiolite N2 Firmware+18 moreJun 17, 2026 Sep 3, 2023 N/A· v4 9.8 CRITICAL· v3 N/A· v2
Synel Terminals - CWE-494: Download of Code Without Integrity Check
|
Buffer Copy without Checking Size of Input ('Classic Buffer Overflow'), Out-of-bounds Write, Download of Code Without Integrity Check vulnerability in Silicon Labs Gecko Bootloader on ARM (Firmware Update File Parser mod...Show more |
Download of Code Without Integrity Check vulnerability in Genians Genian NAC V4.0, Genians Genian NAC V5.0, Genians Genian NAC Suite V5.0, Genians Genian ZTNA allows Malicious Software Update.This issue affects Genian NA...Show more |
1Phoenixcontact 6Wp 6070 Wvps Firmware Wp 6101 Wxps FirmwareWp 6121 Wxps Firmware+3 moreJun 17, 2026 Aug 9, 2023 N/A· v4 7.2 HIGH· v3 N/A· v2 In PHOENIX CONTACTs WP 6xxx series web panels in versions prior to 4.0.10 a remote attacker with SNMPv2 write privileges may use an a special SNMP request to gain full access to the device. |
The filename parameter of the Context.FileAttachment function is not properly sanitized. A maliciously crafted filename can cause the Content-Disposition header to be sent with an unexpected filename value or otherwise m...Show more |
A vulnerability has been discovered in Rocket.Chat, where editing messages can change the original timestamp, causing the UI to display messages in an incorrect order. |
1Electra Air 1Smart Kit For Split Ac Jun 17, 2026 Apr 17, 2023 N/A· v4 6.5 MEDIUM· v3 N/A· v2 Electra Central AC unit – Adjacent attacker may cause the unit to load unauthorized FW. |
1Electra Air 1Central Ac Unit Firmware Jun 17, 2026 Apr 17, 2023 N/A· v4 6.5 MEDIUM· v3 N/A· v2 Electra Central AC unit – Adjacent attacker may cause the unit to load unauthorized FW. |
A download of code without Integrity check vulnerability [CWE-494] in FortiClientMac version 7.0.0 through 7.0.7, 6.4 all versions, 6.2 all versions, 6.0 all versions, 5.6 all versions, 5.4 all versions, 5.2 all version...Show more |
An arbitrary file download vulnerability in the background management module of RuoYi v4.7.6 and below allows attackers to download arbitrary files in the server. |
1Veritas 2Aptare It Analytics Netbackup It AnalyticsJun 17, 2026 Mar 24, 2023 N/A· v4 5.3 MEDIUM· v3 N/A· v2 An issue was discovered in Veritas NetBackup IT Analytics 11 before 11.2.0. The application upgrade process included unsigned files that could be exploited and result in a customer installing unauthentic components. A ma...Show more |
ShadowsocksX-NG 1.10.0 signs with com.apple.security.get-task-allow entitlements because of CODE_SIGNING_INJECT_BASE_ENTITLEMENTS. |
1Netgear 9D6100 Firmware Dgn1000v3 FirmwareR8900 Firmware+6 moreJun 17, 2026 Feb 2, 2023 N/A· v4 7.4 HIGH· v3 N/A· v2 An exploitable firmware modification vulnerability was discovered in certain Netgear products. The data integrity of the uploaded firmware image is ensured with a fixed checksum number. Therefore, an attacker can conduct...Show more |
1Ruckuswireless 14R310 Firmware R500 FirmwareR600 Firmware+11 moreJun 17, 2026 Jan 20, 2023 N/A· v4 9.8 CRITICAL· v3 N/A· v2 In Ruckus R310 10.5.1.0.199, Ruckus R500 10.5.1.0.199, Ruckus R600 10.5.1.0.199, Ruckus T300 10.5.1.0.199, Ruckus T301n 10.5.1.0.199, Ruckus T301s 10.5.1.0.199, SmartCell Gateway 200 (SCG200) before 3.6.2.0.795, SmartZon...Show more |
1Ruckuswireless 14R310 Firmware R500 FirmwareR600 Firmware+11 moreJun 17, 2026 Jan 20, 2023 N/A· v4 9.8 CRITICAL· v3 N/A· v2 In Ruckus R310 10.5.1.0.199, Ruckus R500 10.5.1.0.199, Ruckus R600 10.5.1.0.199, Ruckus T300 10.5.1.0.199, Ruckus T301n 10.5.1.0.199, Ruckus T301s 10.5.1.0.199, SmartCell Gateway 200 (SCG200) before 3.6.2.0.795, SmartZon...Show more |
1Ge 8Inet 900 Firmware Inet Ii 900 FirmwareSd1 Firmware+5 moreJun 17, 2026 Dec 26, 2022 N/A· v4 9.8 CRITICAL· v3 N/A· v2 Certain General Electric Renewable Energy products download firmware without an integrity check. This affects iNET and iNET II before 8.3.0, SD before 6.4.7, TD220X before 2.0.16, and TD220MAX before 1.2.6. |
1Tp Link 4Tl Wr740n V1 Firmware Tl Wr740n V2 FirmwareTl Wr741nd V1 Firmware+1 moreJun 17, 2026 Dec 20, 2022 N/A· v4 4.8 MEDIUM· v3 N/A· v2 TP-Link TL-WR740N V1 and V2 v3.12.4 and earlier allows authenticated attackers to execute arbitrary code or cause a Denial of Service (DoS) via uploading a crafted firmware image during the firmware update process. |
TP-Link TL-WR1043ND V1 3.13.15 and earlier allows authenticated attackers to execute arbitrary code or cause a Denial of Service (DoS) via uploading a crafted firmware image during the firmware update process. |
An exploitable firmware modification vulnerability was discovered on the Netgear WNR2000v1 router. An attacker can conduct a MITM (Man-in-the-Middle) attack to modify the user-uploaded firmware image and bypass the CRC c...Show more |
An authenticated attacker can impact the integrity of the ArubaOS bootloader on 7xxx series controllers. Successful exploitation can compromise the hardware chain of trust on the impacted controller.
|