ZeroHour

Vulnerabilities

4 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2020-9420
+1 in the same advisory: …9419
The login password of the web administrative dashboard in Arcadyan Wifi routers VRV9506JAC23 is sent in cleartext, allowing an attacker to sniff and intercept t

The login password of the web administrative dashboard in Arcadyan Wifi routers VRV9506JAC23 is sent in cleartext, allowing an attacker to sniff and intercept traffic to learn the administrative credentials to the router.

NVD description · AI analysis pending
6.5
group max
<1% PoC
  • arcadyan vrv9506jac23 firmware
CVE-2021-20090
Unauthenticated Path Traversal in Arcadyan Buffalo Router Firmware

CVE-2021-20090 is a path traversal flaw (CWE-22) in the web interface of Arcadyan's Buffalo router firmware. By sending crafted HTTP requests containing directory traversal sequences, an unauthenticated, remote attacker can bypass the device's authentication. Successful exploitation grants access to sensitive information and otherwise protected functionality on the router without valid credentials. The flaw affects multiple router models across several different vendors, because Arcadyan's Buffalo firmware is embedded in a range of OEM and ISP-distributed products. Exploitation is confirmed in the wild: the vulnerability was added to CISA's KEV catalog on 2021-11-03, and EPSS rates the probability of exploitation within 30 days at 100% (100th percentile).

Do: Apply firmware updates from the router vendor as directed in the CISA KEV required action. Until patched, restrict or disable WAN-side remote management of the device's web interface. Review router configurations for unauthorized changes after patching, since unauthenticated remote access was possible.

9.8100% KEV PoC ×2
  • Arcadyan Buffalo Firmware
massplausibly millions of deployed consumer/ISP routers; internet-exposed subset unknown
CVE-2016-10042
Authorization Bypass in the Web interface of Arcadyan SLT-00 Star* (aka Swisscom Internet-Box) devices before R7.7 allows unauthorized reconfiguration of the st

Authorization Bypass in the Web interface of Arcadyan SLT-00 Star* (aka Swisscom Internet-Box) devices before R7.7 allows unauthorized reconfiguration of the static routing table via an unauthenticated HTTP request, leading to denial of service and information disclosure.

NVD description · AI analysis pending
7.51%
  • arcadyan swisscom internet-box firmware