Lucene search

K

Teracue Security Vulnerabilities

cve
cve

CVE-2018-20220

An issue was discovered on Teracue ENC-400 devices with firmware 2.56 and below. While the web interface requires authentication before it can be interacted with, a large portion of the HTTP endpoints are missing authentication. An attacker is able to view these pages before being authenticated,...

7.5CVSS

8.6AI Score

0.002EPSS

2019-03-21 04:00 PM
40
cve
cve

CVE-2018-20219

An issue was discovered on Teracue ENC-400 devices with firmware 2.56 and below. After successful authentication, the device sends an authentication cookie to the end user such that they can access the devices web administration panel. This token is hard-coded to a string in the source code...

8.1CVSS

9.1AI Score

0.006EPSS

2019-03-21 04:00 PM
41
cve
cve

CVE-2018-20218

An issue was discovered on Teracue ENC-400 devices with firmware 2.56 and below. The login form passes user input directly to a shell command without any kind of escaping or validation in /usr/share/www/check.lp file. An attacker is able to perform command injection using the "password" parameter.....

9.8CVSS

9.7AI Score

0.006EPSS

2019-03-21 04:00 PM
39