← Back

Mercury X18g Firmware

mercury_x18g_firmware

Vendor: Mercusys • 4 CVEs

CVEs (4)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Mercusys
1Mercury X18g Firmware
Nov 21, 2024
Apr 29, 2021
N/A· v4
7.5 HIGH· v3
7.8 HIGH· v2
MERCUSYS Mercury X18G 1.0.5 devices allow Denial of service via a crafted value to the POST listen_http_lan parameter. Upon subsequent device restarts after this vulnerability is exploted the device will not be able to a...Show more
MERCUSYS Mercury X18G 1.0.5 devices allow Denial of service via a crafted value to the POST listen_http_lan parameter. Upon subsequent device restarts after this vulnerability is exploted the device will not be able to access the webserver unless the listen_http_lan parameter to uhttpd.json is manually fixed.Show less
1Mercusys
1Mercury X18g Firmware
Nov 21, 2024
Apr 29, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Cross site Scripting (XSS) vulnerability in MERCUSYS Mercury X18G 1.0.5 devices, via crafted values to the 'src_dport_start', 'src_dport_end', and 'dest_port' parameters.
1Mercusys
1Mercury X18g Firmware
Nov 21, 2024
Jan 7, 2021
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
MERCUSYS Mercury X18G 1.0.5 devices allow Directory Traversal via ../ to the UPnP server, as demonstrated by the /../../conf/template/uhttpd.json URI.
1Mercusys
1Mercury X18g Firmware
Nov 21, 2024
Jan 7, 2021
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
MERCUSYS Mercury X18G 1.0.5 devices allow Directory Traversal via ../ in conjunction with a loginLess or login.htm URI (for authentication bypass) to the web server, as demonstrated by the /loginLess/../../etc/passwd URI...Show more
MERCUSYS Mercury X18G 1.0.5 devices allow Directory Traversal via ../ in conjunction with a loginLess or login.htm URI (for authentication bypass) to the web server, as demonstrated by the /loginLess/../../etc/passwd URI.Show less