← Back

I Onenet

i-onenet

Vendor: Hunesion • 3 CVEs

CVEs (3)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Hunesion
1I Onenet
Nov 21, 2024
Feb 27, 2020
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
Incorrect Access Control in Hunesion i-oneNet 3.0.6042.1200 allows the local user to access other user's information which is unauthorized via brute force.
1Hunesion
1I Onenet
Jun 17, 2026
Jul 10, 2019
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
In Hunesion i-oneNet version 3.0.7 ~ 3.0.53 and 4.0.4 ~ 4.0.16, due to the lack of update file integrity checking in the upgrade process, an attacker can craft malicious file and use it as an update.
1Hunesion
1I Onenet
Jun 17, 2026
Jul 10, 2019
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
In Hunesion i-oneNet version 3.0.7 ~ 3.0.53 and 4.0.4 ~ 4.0.16, the specific upload web module doesn't verify the file extension and type, and an attacker can upload a webshell. After the webshell upload, an attacker can...Show more
In Hunesion i-oneNet version 3.0.7 ~ 3.0.53 and 4.0.4 ~ 4.0.16, the specific upload web module doesn't verify the file extension and type, and an attacker can upload a webshell. After the webshell upload, an attacker can use the webshell to perform remote code exection such as running a system command.Show less