Edward Warren
72 exploits
Active since Jun 2023
KAYSUS KS-WR3600 Firmware 1.0.5.9.1 - Unauthenticated Root Shell Access via SSH
CVSS 8.4
KuwFi AC900 Firmware 1.0.13 - Stack-based Buffer Overflow via formMultiApnSetting Pincode Parameter
CVSS 9.8
Panda Wireless PWRU0 <2.2.9 - Privilege Escalation
CVSS 9.1
Adtran 834-5 <11.1.0.101 - Command Injection
CVSS 8.8
FIRSTNUM JC21A-04 - Command Injection
CVSS 7.4
Jointelli 5G CPE 21H01 - Command Injection
CVSS 7.4
FIRSTNUM JC21A-04 - Info Disclosure
CVSS 6.5
Shenzhen Tuoshi NR500-EA RG500UEAABxCOMSLICv3.4.2731.16.43 - Hard-coded Root Account
CVSS 9.8
KuWFi CPF908-CP5 WEB5.0_LCD_20210125 - Info Disclosure
CVSS 9.1
KuwFi GC111 CPE-LM321_V3.2 GC111-GL-LM321_V3.0_20191211 - Unauthenticated OS Command Injection via SSID Parameter
CVSS 9.8
KuwFi GC111 GC111-GL-LM321_V3.0_20191211 - Unauthenticated Exposure of Sensitive Information via TELNET Service
CVSS 9.8
KuWFi 5G01-X55 FL2020_V0.0.12 - Info Disclosure
CVSS 7.5
KAYSUS KS-WR3600 1.0.5.9.1 - Auth Bypass
CVSS 9.4
7-Eleven Hello Cup 1.3.1 - Unauthenticated BLE Connection Bypass
CVSS 6.5
Viatom Health ViHealth <2.74.58 - RCE
CVSS 7.8
Arris DG860A and DG1670A - Unauthenticated Remote Access via Predictable WPA2 PSK
CVSS 8.8
ARRIS TG852G TG862G TG1672G - Unauthenticated WPA2-PSK Derivation via Beacon Frame
CVSS 9.8
Technicolor TC8715D - Info Disclosure
CVSS 8.8
Ubee DDW365 XCNDDW365 - Use of Hard-coded Credentials via Predictable WPA2 PSK
CVSS 8.8
Technicolor TC8715D 01.EF.04.38.00 Stored XSS via User Name in dyn_dns.asp
CVSS 5.4
Technicolor TC8715D TC8715D-01.EF.04.38.00 Stored XSS via User Defined Service in managed_services_add.asp
CVSS 6.1
UBEE DDW365 XCNDDW365 <8.14.3105 - Stored XSS
CVSS 7.2
EnGenius ESR580 A8J-EMR5000 - Stored Cross-Site Scripting via Wi-Fi SSID Input Fields
CVSS 4.3
Hitron CODA-4582 2AHKM-CODA4589 7.2.4.5.1b8 - Stored Cross-Site Scripting via Network Name (SSID) Input
CVSS 5.2
EnGenius EWS356-Fit Firmware <= 1.1.30 - Stored Cross-Site Scripting via Wi-Fi SSID Parameter
CVSS 4.8