Mercusys
mercusys
7 CVEs • 6 products
Products (6)
Click to collapseToggle
Products (6)
Click to collapse
CVEs (7)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Mercusys MW305R 3.30 and below is has a Transport Layer Security (TLS) certificate private key disclosure. |
3Fastcom MercusysTp Link6Fac1900r Firmware Mercury D196g FirmwareTl Wdr5660 Firmware+3 moreNov 21, 2024 May 10, 2022 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 TP-Link TL-WDR7660 2.0.30, Mercury D196G 20200109_2.0.4, and Fast FAC1900R 20190827_2.0.2 routers have a stack overflow issue in `MntAte` function. Local users could get remote code execution. |
3Fastcom MercusysTp Link6Fac1900r Firmware Mercury D196g FirmwareTl Wdr5660 Firmware+3 moreNov 21, 2024 May 10, 2022 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 TP-Link TL-WDR7660 2.0.30, Mercury D196G 20200109_2.0.4, and Fast FAC1900R 20190827_2.0.2 routers have a stack overflow issue in `MmtAtePrase` function. Local users could get remote code execution. |
1Mercusys 1Mercury X18g Firmware Nov 21, 2024 Apr 29, 2021 N/A· v4 7.5 HIGH· v3 7.8 HIGH· v2 MERCUSYS Mercury X18G 1.0.5 devices allow Denial of service via a crafted value to the POST listen_http_lan parameter. Upon subsequent device restarts after this vulnerability is exploted the device will not be able to a...Show more |
1Mercusys 1Mercury X18g Firmware Nov 21, 2024 Apr 29, 2021 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Cross site Scripting (XSS) vulnerability in MERCUSYS Mercury X18G 1.0.5 devices, via crafted values to the 'src_dport_start', 'src_dport_end', and 'dest_port' parameters. |
1Mercusys 1Mercury X18g Firmware Nov 21, 2024 Jan 7, 2021 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 MERCUSYS Mercury X18G 1.0.5 devices allow Directory Traversal via ../ to the UPnP server, as demonstrated by the /../../conf/template/uhttpd.json URI. |
1Mercusys 1Mercury X18g Firmware Nov 21, 2024 Jan 7, 2021 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 MERCUSYS Mercury X18G 1.0.5 devices allow Directory Traversal via ../ in conjunction with a loginLess or login.htm URI (for authentication bypass) to the web server, as demonstrated by the /loginLess/../../etc/passwd URI...Show more |