ZeroHour

Vulnerabilities

14 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2023-22441
+2 in the same advisory: …25184 …23901
Missing authentication for critical function exists in Seiko Solutions SkyBridge series, which may allow a remote attacker to obtain or alter the setting inform

Missing authentication for critical function exists in Seiko Solutions SkyBridge series, which may allow a remote attacker to obtain or alter the setting information of the product or execute some critical functions without authentication, e.g., rebooting the product. Affected products and versions are as follows: SkyBridge MB-A200 firmware Ver. 01.00.05 and earlier, and SkyBridge BASIC MB-A130 firmware Ver. 1.4.1 and earlier

NVD description · AI analysis pending
8.6
group max
<1%
  • seiko-sol skybridge basic mb-a130 firmware
  • seiko-sol skybridge mb-a200 firmware
CVE-2023-23906
+4 in the same advisory: …25072 …22361 …24586 …25070
Missing authentication for critical function exists in SkyBridge MB-A100/110 firmware Ver.

Missing authentication for critical function exists in SkyBridge MB-A100/110 firmware Ver. 4.2.0 and earlier, which may allow a remote unauthenticated attacker to execute some critical functions without authentication, e.g., rebooting the product.

NVD description · AI analysis pending
7.5
group max
1%
  • seiko-sol skybridge mb-a110 firmware
  • seiko-sol skybridge mb-a100 firmware
CVE-2023-23578
Improper access control vulnerability in SkyBridge MB-A200 firmware Ver.

Improper access control vulnerability in SkyBridge MB-A200 firmware Ver. 01.00.05 and earlier allows a remote unauthenticated attacker to connect to the product's ADB port.

NVD description · AI analysis pending
7.52%
  • seiko-sol skybridge mb-a200 firmware
CVE-2022-36559
+1 in the same advisory: …36560
Seiko SkyBridge MB-A200 v01.00.04 and below was discovered to contain a command injection vulnerability via the Ping parameter at ping_exec.cgi.

Seiko SkyBridge MB-A200 v01.00.04 and below was discovered to contain a command injection vulnerability via the Ping parameter at ping_exec.cgi.

NVD description · AI analysis pending
9.82%
  • seiko-sol skybridge mb-a200 firmware
CVE-2022-36556
+2 in the same advisory: …36557 …36558
Seiko SkyBridge MB-A100/A110 v4.2.0 and below was discovered to contain a command injection vulnerability via the ipAddress parameter at 07system08execute_ping_

Seiko SkyBridge MB-A100/A110 v4.2.0 and below was discovered to contain a command injection vulnerability via the ipAddress parameter at 07system08execute_ping_01.

NVD description · AI analysis pending
9.82%
  • seiko-sol skybridge mb-a100 firmware
  • seiko-sol skybridge mb-a110 firmware