Lucene search

K

Chinamobile Security Vulnerabilities

cve
cve

CVE-2018-20326

ChinaMobile PLC Wireless Router GPN2.4P21-C-CN devices with firmware W2001EN-00 have XSS via the cgi-bin/webproc?getpage=html/index.html var:subpage parameter.

6.1CVSS

5.8AI Score

0.001EPSS

2019-01-02 06:29 PM
42
cve
cve

CVE-2021-25812

Command injection vulnerability in China Mobile An Lianbao WF-1 1.01 via the 'ip' parameter with a POST request to /api/ZRQos/set_online_client.

9.8CVSS

9.4AI Score

0.022EPSS

2021-04-29 04:15 PM
18
cve
cve

CVE-2021-30228

The api/ZRAndlink/set_ZRAndlink interface in China Mobile An Lianbao WF-1 router 1.0.1 allows remote attackers to execute arbitrary commands via shell metacharacters in the iandlink_proc_enable parameter.

9.8CVSS

9.8AI Score

0.008EPSS

2021-04-29 04:15 PM
27
3
cve
cve

CVE-2021-30229

The api/zrDm/set_zrDm interface in China Mobile An Lianbao WF-1 router 1.0.1 allows remote attackers to execute arbitrary commands via shell metacharacters in the dm_enable, AppKey, or Pwd parameter.

8.8CVSS

9AI Score

0.027EPSS

2021-04-29 04:15 PM
17
2
cve
cve

CVE-2021-30230

The api/ZRFirmware/set_time_zone interface in China Mobile An Lianbao WF-1 router 1.0.1 allows remote attackers to execute arbitrary commands via shell metacharacters in the zonename parameter.

9.8CVSS

9.8AI Score

0.008EPSS

2021-04-29 04:15 PM
22
3
cve
cve

CVE-2021-30231

The api/zrDm/set_ZRElink interface in China Mobile An Lianbao WF-1 router 1.0.1 allows remote attackers to execute arbitrary commands via shell metacharacters in the bssaddr, abiaddr, devtoken, devid, elinksync, or elink_proc_enable parameter.

9.8CVSS

9.8AI Score

0.008EPSS

2021-04-29 04:15 PM
23
2
cve
cve

CVE-2021-30232

The api/ZRIGMP/set_IGMP_PROXY interface in China Mobile An Lianbao WF-1 router 1.0.1 allows remote attackers to execute arbitrary commands via shell metacharacters in the IGMP_PROXY_WAN_CONNECT parameter.

9.8CVSS

9.8AI Score

0.008EPSS

2021-04-29 04:15 PM
24
5
cve
cve

CVE-2021-30233

The api/ZRIptv/setIptvInfo interface in China Mobile An Lianbao WF-1 router 1.0.1 allows remote attackers to execute arbitrary commands via shell metacharacters in the iptv_vlan parameter.

9.8CVSS

9.8AI Score

0.008EPSS

2021-04-29 04:15 PM
21
5
cve
cve

CVE-2021-30234

The api/ZRIGMP/set_MLD_PROXY interface in China Mobile An Lianbao WF-1 router 1.0.1 allows remote attackers to execute arbitrary commands via shell metacharacters in the MLD_PROXY_WAN_CONNECT parameter.

9.8CVSS

9.8AI Score

0.008EPSS

2021-04-29 04:15 PM
24
3
cve
cve

CVE-2021-33963

China Mobile An Lianbao WF-1 v1.0.1 router web interface through /api/ZRMacClone/mac_addr_clone receives parameters by POST request, and the parameter macType has a command injection vulnerability. An attacker can use the vulnerability to execute remote commands.

9.8CVSS

9.7AI Score

0.007EPSS

2022-01-15 10:15 AM
39
cve
cve

CVE-2021-33964

China Mobile An Lianbao WF-1 V1.0.1 router provides a web interface /api/ZRRuleFilter/set_firewall_level which receives parameters by POST request, and the parameter firewall_level has a command injection vulnerability. An attacker can use the vulnerability to execute remote commands.

8.8CVSS

8.9AI Score

0.004EPSS

2022-01-18 12:15 PM
31
cve
cve

CVE-2021-33965

China Mobile An Lianbao WF-1 V1.0.1 router provides a web interface /api/ZRMesh/set_ZRMesh which receives parameters by POST request, and the parameter mesh_enable and mesh_device have a command injection vulnerability. An attacker can use the vulnerability to execute remote commands.

8.8CVSS

8.9AI Score

0.004EPSS

2022-01-18 01:15 PM
28
cve
cve

CVE-2023-41011

Command Execution vulnerability in China Mobile Communications China Mobile Intelligent Home Gateway v.HG6543C4 allows a remote attacker to execute arbitrary code via the shortcut_telnet.cg component.

9.8CVSS

9.6AI Score

0.004EPSS

2023-09-14 07:16 PM
19
cve
cve

CVE-2023-41012

An issue in China Mobile Communications China Mobile Intelligent Home Gateway v.HG6543C4 allows a remote attacker to execute arbitrary code via the authentication mechanism.

9.8CVSS

9.7AI Score

0.01EPSS

2023-09-05 04:15 PM
26