HIGH🇵🇱 Wersja polska

CVE-2018-14783

CVSS 8.8v3.0pub. 2018-08-10upd. 2024-11-21

NetComm Wireless G LTE Light Industrial M2M Router (NWL-25) with firmware 2.0.29.11 and prior. A cross-site request forgery condition can occur, allowing an attacker to change passwords of the device remotely.

CVSS Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
  • Netcommwireless Nwl 25

    HW
    Netcommwireless
    all versions
  • Netcommwireless Nwl 25 Firmware

    OS
    Netcommwireless
    ≤ 2.0.29.11
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2018-14782HIGH7.5same product

NetComm Wireless G LTE Light Industrial M2M Router (NWL-25) with firmware 2.0.29.11 and prior. The device allo...

CVE-2018-14785HIGH7.5same product

NetComm Wireless G LTE Light Industrial M2M Router (NWL-25) with firmware 2.0.29.11 and prior. The directory o...

CVE-2018-14784MEDIUM6.1same product

NetComm Wireless G LTE Light Industrial M2M Router (NWL-25) with firmware 2.0.29.11 and prior. The device is v...

CVE-2022-4873CRITICAL9.8PL ✓same vendor

Stack-based buffer overflow w parametrze sessionKey na routerach Netcomm

CVE-2015-6024CRITICAL9.8PL ✓same vendor

Command injection w ping.cgi routerów NetCommWireless HSPA 3G10WVE