Lucene search

K

Verve Connect Vh510 Firmware Security Vulnerabilities

cve
cve

CVE-2020-27689

The Relish (Verve Connect) VH510 device with firmware before 1.0.1.6L0516 contains undocumented default admin credentials for the web management interface. A remote attacker could exploit this vulnerability to login and execute commands on the device, as well as upgrade the firmware image to a mali...

9.8CVSS

9.5AI Score

0.009EPSS

2020-11-04 08:15 PM
27
cve
cve

CVE-2020-27690

The Relish (Verve Connect) VH510 device with firmware before 1.0.1.6L0516 contains a buffer overflow within its web management portal. When a POST request is sent to /boaform/admin/formDOMAINBLK with a large blkDomain value, the Boa server crashes.

5.5CVSS

5.8AI Score

0.0004EPSS

2020-11-04 09:15 PM
36
cve
cve

CVE-2020-27691

The Relish (Verve Connect) VH510 device with firmware before 1.0.1.6L0516 allows XSS via URLBlocking Settings, SNMP Settings, and System Log Settings.

6.1CVSS

5.9AI Score

0.001EPSS

2020-11-04 09:15 PM
36
cve
cve

CVE-2020-27692

The Relish (Verve Connect) VH510 device with firmware before 1.0.1.6L0516 contains multiple CSRF vulnerabilities within its web management portal. Attackers can, for example, use this to update the TR-069 configuration server settings (responsible for managing devices remotely). This makes it possi...

8.8CVSS

8.8AI Score

0.002EPSS

2020-11-04 09:15 PM
25