ZeroHour

Vulnerabilities

13 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2024-45836
Cross-site scripting vulnerability exists in the web management page of PLANEX COMMUNICATIONS network cameras.

Cross-site scripting vulnerability exists in the web management page of PLANEX COMMUNICATIONS network cameras. If a logged-in user accesses a specific file, an arbitrary script may be executed on the web browser of the user.

NVD description · AI analysis pending
6.1<1%
  • planex cs-qr10 firmware
  • planex cs-qr20 firmware
  • planex cs-qr22 firmware
  • +1 more
CVE-2024-45372
MZK-DP300N firmware versions 1.04 and earlier contains a cross-site request forger vulnerability.

MZK-DP300N firmware versions 1.04 and earlier contains a cross-site request forger vulnerability. Viewing a malicious page while logging in to the web management page of the affected product may lead the user to perform unintended operations such as changing the login password, etc.

NVD description · AI analysis pending
6.5<1%
  • planex mzk-dp300n firmware
CVE-2024-30220
+1 in the same advisory: …30219
Command injection vulnerability in PLANEX COMMUNICATIONS wireless LAN routers allows a network-adjacent unauthenticated attacker to execute an arbitrary command

Command injection vulnerability in PLANEX COMMUNICATIONS wireless LAN routers allows a network-adjacent unauthenticated attacker to execute an arbitrary command by sending a specially crafted request to a certain port. Note that MZK-MF300N is no longer supported, therefore the update for this product is not provided.

NVD description · AI analysis pending
8.8
group max
1%
  • planex mzk-mf300n firmware
  • planex mzk-mf300hp2 firmware
CVE-2023-22375
+1 in the same advisory: …22376
Cross-site request forgery (CSRF) vulnerability in Wired/Wireless LAN Pan/Tilt Network Camera CS-WMV02G all versions allows a remote unauthenticated attacker to

Cross-site request forgery (CSRF) vulnerability in Wired/Wireless LAN Pan/Tilt Network Camera CS-WMV02G all versions allows a remote unauthenticated attacker to hijack the authentication and conduct arbitrary operations by having a logged-in user to view a malicious page. NOTE: This vulnerability only affects products that are no longer supported by the developer.

NVD description · AI analysis pending
8.8
group max
<1%
  • planex cs-wmv02g firmware
CVE-2023-22370
Stored cross-site scripting vulnerability in Wired/Wireless LAN Pan/Tilt Network Camera CS-WMV02G all versions allows a network-adjacent authenticated attacker

Stored cross-site scripting vulnerability in Wired/Wireless LAN Pan/Tilt Network Camera CS-WMV02G all versions allows a network-adjacent authenticated attacker to inject an arbitrary script. NOTE: This vulnerability only affects products that are no longer supported by the developer.

NVD description · AI analysis pending
5.2<1%
  • planex cs-wmv02g
CVE-2022-38399
Missing protection mechanism for alternate hardware interface in SmaCam CS-QR10 all versions and SmaCam Night Vision CS-QR20 all versions allows an attacker to

Missing protection mechanism for alternate hardware interface in SmaCam CS-QR10 all versions and SmaCam Night Vision CS-QR20 all versions allows an attacker to execute an arbitrary OS command by having the product connect to the product's specific serial connection

NVD description · AI analysis pending
6.8<1%
  • planex cs-qr20 firmware
  • planex cs-qr10 firmware
CVE-2021-37289
Insecure Permissions in administration interface in Planex MZK-DP150N 1.42 and 1.43 allows attackers to execute system command as root via etc_ro/web/syscmd.asp

Insecure Permissions in administration interface in Planex MZK-DP150N 1.42 and 1.43 allows attackers to execute system command as root via etc_ro/web/syscmd.asp.

NVD description · AI analysis pending
7.22% PoC
  • planex mzk-dp150n firmware
CVE-2017-12577
+1 in the same advisory: …12576
An issue was discovered on the PLANEX CS-QR20 1.30.

An issue was discovered on the PLANEX CS-QR20 1.30. A hardcoded account / password ("admin:password") is used in the Android application that allows attackers to use a hidden API URL "/goform/SystemCommand" to execute any command with root permission.

NVD description · AI analysis pending
9.8
group max
1%
  • planex cs-qr20 firmware
  • planex smacam night vision
CVE-2017-12574
+1 in the same advisory: …12573
An issue was discovered on PLANEX CS-W50HD devices with firmware before 030720.

An issue was discovered on PLANEX CS-W50HD devices with firmware before 030720. A hardcoded credential "supervisor:dangerous" was injected into web authentication database "/.htpasswd" during booting process, which allows attackers to gain unauthorized access and control the device completely; the account can't be modified or deleted.

NVD description · AI analysis pending
9.8
group max
2%
  • planex cs-w50hd firmware