TanYeeTat

2 exploits Active since Feb 2023
CVE-2022-45599 NOMISEC CRITICAL WRITEUP
Aztech WMB250AC Firmware 016 2020 - PHP Type Juggling in login.php
Aztech WMB250AC Mesh Routers Firmware Version 016 2020 is vulnerable to PHP Type Juggling in file /var/www/login.php, allows attackers to gain escalated privileges only when specific conditions regarding a given accounts hashed password.
CVSS 9.8
CVE-2022-45600 NOMISEC HIGH WORKING POC
Aztech WMB250AC Firmware 016 2020 - Unauthenticated Remote Code Execution via Session Bypass
Aztech WMB250AC Mesh Routers Firmware Version 016 2020 devices improperly manage sessions, which allows remote attackers to bypass authentication in opportunistic circumstances and execute arbitrary commands with administrator privileges by leveraging an existing web portal login.
CVSS 8.8