ZeroHour

Vulnerabilities

10 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2022-35222
HiCOS Citizen verification component has a stack-based buffer overflow vulnerability due to insufficient parameter length validation.

HiCOS Citizen verification component has a stack-based buffer overflow vulnerability due to insufficient parameter length validation. An unauthenticated physical attacker can exploit this vulnerability to execute arbitrary code, manipulate system command or disrupt service.

NVD description · AI analysis pending
6.8<1%
  • hinet hicos natural person credential component client
CVE-2022-32961
+3 in the same advisory: …32960 …32959 …32962
HICOS’ client-side citizen digital certificate component has a stack-based buffer overflow vulnerability when reading IC card due to insufficient parameter leng

HICOS’ client-side citizen digital certificate component has a stack-based buffer overflow vulnerability when reading IC card due to insufficient parameter length validation for token information. An unauthenticated physical attacker can exploit this vulnerability to execute arbitrary code, manipulate system data or terminate service.

NVD description · AI analysis pending
6.8<1%
  • hinet hicos natural person credential component client
CVE-2019-15066
+4 in the same advisory: …15064 …13411 …15065 …13412
An “invalid command” handler issue was discovered in HiNet GPON firmware < I040GWR190731.

An “invalid command” handler issue was discovered in HiNet GPON firmware < I040GWR190731. It allows an attacker to execute arbitrary command through port 6998. CVSS 3.0 Base score 10.0. CVSS vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H).

NVD description · AI analysis pending
9.8
group max
2%
  • hinet gpon firmware