Genexis
genexis
8 CVEs • 3 products
Products (3)
Click to collapseToggle
Products (3)
Click to collapse
CVEs (8)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
A vulnerability has been identified in Genexis Platinum P4410 router (Firmware P4410-V2–1.41) that allows a local network attacker to achieve Remote Code Execution (RCE) with root privileges. The issue occurs due to impr...Show more |
1Genexis 1Platinum 4410 Firmware Nov 21, 2024 Nov 10, 2021 N/A· v4 6.5 MEDIUM· v3 7.1 HIGH· v2 Cross site request forgery (CSRF) in Genexis Platinum 4410 V2-1.28, allows attackers to cause a denial of service by continuously restarting the router. |
1Genexis 1Platinum 4410 Firmware Nov 21, 2024 Apr 13, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Genexis PLATINUM 4410 2.1 P4410-V2-1.28 devices allow remote attackers to execute arbitrary code via shell metacharacters to sys_config_valid.xgi, as demonstrated by the sys_config_valid.xgi?exeshell=%60telnetd%20%26%60...Show more |
1Genexis 1Platinum 4410 Firmware Nov 21, 2024 Nov 17, 2020 N/A· v4 6.5 MEDIUM· v3 3.3 LOW· v2 UPNP Service listening on port 5555 in Genexis Platinum 4410 Router V2.1 (P4410-V2–1.34H) has an action 'X_GetAccess' which leaks the credentials of 'admin', provided that the attacker is network adjacent. |
1Genexis 1Platinum 4410 Firmware Nov 21, 2024 Oct 28, 2020 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 Genexis Platinum-4410 P4410-V2-1.28 devices allow stored XSS in the WLAN SSID parameter. This could allow an attacker to perform malicious actions in which the XSS popup will affect all privileged users. |
1Genexis 1Platinum 4410 Firmware Nov 21, 2024 Sep 16, 2020 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 A specific router allows changing the Wi-Fi password remotely. Genexis Platinum 4410 V2-1.28, a compact router generally used at homes and offices was found to be vulnerable to Broken Access Control and CSRF which could...Show more |
1Genexis 1Platinum 4410 Firmware Nov 21, 2024 Jan 8, 2020 N/A· v4 9.8 CRITICAL· v3 5.0 MEDIUM· v2 An authentication bypass vulnerability on Genexis Platinum-4410 v2.1 P4410-V2 1.28 devices allows attackers to obtain cleartext credentials from the HTML source code of the cgi-bin/index2.asp URI. |
CPEs used by subscribers on the access network receive their individual configuration settings from a central GAPS instance. A CPE identifies itself by the MAC address of its WAN interface and a certain "chk" value (48bi...Show more |