ZeroHour

Vulnerabilities

12 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2022-4873
+1 in the same advisory: …4874
On Netcomm router models NF20MESH, NF20, and NL1902 a stack based buffer overflow affects the sessionKey parameter.

On Netcomm router models NF20MESH, NF20, and NL1902 a stack based buffer overflow affects the sessionKey parameter. By providing a specific number of bytes, the instruction pointer is able to be overwritten on the stack and crashes the application at a known location.

NVD description · AI analysis pending
9.8
group max
7% PoC
  • netcommwireless nf20 firmware
  • netcommwireless nf20mesh firmware
  • netcommwireless nl1902 firmware
CVE-2019-6018
Cross-site scripting vulnerability in NetCommons 3.2.2 and earlier (NetCommons3.x) allows remote attackers to inject arbitrary web script or HTML via unspecifie

Cross-site scripting vulnerability in NetCommons 3.2.2 and earlier (NetCommons3.x) allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

NVD description · AI analysis pending
6.1<1%
  • netcommons netcommons
CVE-2018-14783
+3 in the same advisory: …14785 …14782 …14784
NetComm Wireless G LTE Light Industrial M2M Router (NWL-25) with firmware 2.0.29.11 and prior.

NetComm Wireless G LTE Light Industrial M2M Router (NWL-25) with firmware 2.0.29.11 and prior. A cross-site request forgery condition can occur, allowing an attacker to change passwords of the device remotely.

NVD description · AI analysis pending
8.8
group max
<1%
  • netcommwireless nwl-25 firmware
CVE-2017-11645
+2 in the same advisory: …11646 …11647
NetComm Wireless 4GT101W routers with Hardware:

NetComm Wireless 4GT101W routers with Hardware: 0.01 / Software: V1.1.8.8 / Bootloader: 1.1.3 do not require authentication for logfile.html, status.html, or system_config.html.

NVD description · AI analysis pending
9.8
group max
1%
  • netcomm 4gt101w software
  • netcomm 4gt101w bootloader
CVE-2017-5900
Cross-site scripting (XSS) vulnerability in the NetComm NB16WV-02 router with firmware NB16WV_R0.09 allows remote authenticated users to inject arbitrary web sc

Cross-site scripting (XSS) vulnerability in the NetComm NB16WV-02 router with firmware NB16WV_R0.09 allows remote authenticated users to inject arbitrary web script or HTML via the S801F0334 parameter to hdd.htm.

NVD description · AI analysis pending
5.4<1%
  • netcomm nb16wv-02 firmware
CVE-2016-4813
NetCommons 2.4.2.1 and earlier allows remote authenticated secretariat (aka CLERK) users to gain privileges by creating a SYSTEM_ADMIN account.

NetCommons 2.4.2.1 and earlier allows remote authenticated secretariat (aka CLERK) users to gain privileges by creating a SYSTEM_ADMIN account.

NVD description · AI analysis pending
8.82%
  • netcommons netcommons