ZeroHour

Vulnerabilities

4 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2023-26921
OS Command Injection vulnerability in quectel AG550QCN allows attackers to execute arbitrary commands via ql_atfwd.

OS Command Injection vulnerability in quectel AG550QCN allows attackers to execute arbitrary commands via ql_atfwd.

NVD description · AI analysis pending
9.83% PoC
  • quectel ag550qcn firmware
CVE-2022-26147
The Quectel RG502Q-EA modem before 2022-02-23 allow OS Command Injection.

The Quectel RG502Q-EA modem before 2022-02-23 allow OS Command Injection.

NVD description · AI analysis pending
9.83% PoC
  • quectel rg502q-ea firmware
CVE-2021-45815
Quectel UC20 UMTS/HSPA+ UC20 6.3.14 is affected by a Cross Site Scripting (XSS) vulnerability.

Quectel UC20 UMTS/HSPA+ UC20 6.3.14 is affected by a Cross Site Scripting (XSS) vulnerability.

NVD description · AI analysis pending
6.1<1%
  • quectel uc20 firmware
CVE-2021-31698
Quectel EG25-G devices through 202006130814 allow executing arbitrary code remotely by using an AT command to place shell metacharacters in quectel_handle_fumo_

Quectel EG25-G devices through 202006130814 allow executing arbitrary code remotely by using an AT command to place shell metacharacters in quectel_handle_fumo_cfg input in atfwd_daemon.

NVD description · AI analysis pending
9.82% PoC
  • quectel eg25-g firmware