← Back

Juplink

juplink

7 CVEs • 2 products

Products (2)

Click to collapse
Toggle
Rx4 1500
rx4-1500

CVEs (7)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Juplink
1Rx4 1500 Firmware
Nov 21, 2024
Sep 22, 2023
N/A· v4
8.8 HIGH· v3
7.7 HIGH· v2
Command injection in homemng.htm in Juplink RX4-1500 versions V1.0.2, V1.0.3, V1.0.4, and V1.0.5 allows remote authenticated attackers to execute commands via specially crafted requests to the vulnerable endpoint.
1Juplink
1Rx4 1500 Firmware
Nov 21, 2024
Sep 22, 2023
N/A· v4
8.8 HIGH· v3
7.7 HIGH· v2
Command injection vulnerability in the homemng.htm endpoint in Juplink RX4-1500 Wifi router firmware versions V1.0.2, V1.0.3, V1.0.4, and V1.0.5 allows authenticated remote attackers to execute commands as root via speci...Show more
Command injection vulnerability in the homemng.htm endpoint in Juplink RX4-1500 Wifi router firmware versions V1.0.2, V1.0.3, V1.0.4, and V1.0.5 allows authenticated remote attackers to execute commands as root via specially crafted HTTP requests to the vulnerable endpoint.Show less
1Juplink
1Rx4 1500 Firmware
Nov 21, 2024
Sep 22, 2023
N/A· v4
8.8 HIGH· v3
7.7 HIGH· v2
Credential disclosure in the '/webs/userpasswd.htm' endpoint in Juplink RX4-1500 Wifi router firmware versions V1.0.4 and V1.0.5 allows an authenticated attacker to leak the password for the administrative account via re...Show more
Credential disclosure in the '/webs/userpasswd.htm' endpoint in Juplink RX4-1500 Wifi router firmware versions V1.0.4 and V1.0.5 allows an authenticated attacker to leak the password for the administrative account via requests to the vulnerable endpoint. Show less
1Juplink
1Rx4 1500 Firmware
Nov 21, 2024
Sep 18, 2023
N/A· v4
9.8 CRITICAL· v3
5.8 MEDIUM· v2
Hard-coded credentials in Juplink RX4-1500 versions V1.0.2 through V1.0.5 allow unauthenticated attackers to log in to the web interface or telnet service as the 'user' user.
1Juplink
1Rx4 1500 Firmware
Nov 21, 2024
Aug 23, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
A stack-based buffer overflow exists in Juplink RX4-1500, a WiFi router, in versions 1.0.2 through 1.0.5. An authenticated attacker can exploit this vulnerability to achieve code execution as root.
1Juplink
1Rx4 1500 Firmware
Nov 21, 2024
Apr 23, 2020
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
httpd in Juplink RX4-1500 v1.0.3-v1.0.5 allows remote attackers to change or access router settings by connecting to the unauthenticated setup3.htm endpoint from the local network.
1Juplink
1Rx4 1500 Firmware
Nov 21, 2024
Apr 23, 2020
N/A· v4
6.7 MEDIUM· v3
6.9 MEDIUM· v2
Juplink RX4-1500 v1.0.3 allows remote attackers to gain root access to the Linux subsystem via an unsanitized exec call (aka Command Line Injection), if the undocumented telnetd service is enabled and the attacker can au...Show more
Juplink RX4-1500 v1.0.3 allows remote attackers to gain root access to the Linux subsystem via an unsanitized exec call (aka Command Line Injection), if the undocumented telnetd service is enabled and the attacker can authenticate as admin from the local network.Show less