X41 D-Sec GmbH
17 exploits
Active since Apr 2016
Peplink Balance Firmware - Unauthenticated Sensitive Information Exposure via HASync Debug Endpoint
CVSS 5.3
Peplink Balance 305 380 580 710 1350 2500 Firmware - Cross-Site Scripting via orig_url Parameter
CVSS 6.1
Peplink Balance 305 380 580 710 1350 2500 Firmware - Cross-Site Scripting via syncid Parameter
CVSS 6.1
Peplink Balance Firmware Cleartext Password Storage in /etc/waipass and /etc/roapass
CVSS 9.8
Peplink Balance 305, 380, 580, 710, 1350, and 2500 Firmware - Cross-Site Request Forgery in Administrative CGI Scripts
CVSS 8.8
Peplink Balance 305, 380, 580, 710, 1350, and 2500 Firmware < 7.0.1-build2093 - SQL Injection via bauth Cookie
CVSS 9.8
psftpd 10.0.4 Build 729 - Log Injection via CSV Escape Bypass
CVSS 5.3
Peplink Balance 305, 380, 580, 710, 1350, and 2500 Firmware < 7.0.1-build2093 - SQL Injection via bauth Cookie
CVSS 9.8
PSFTPd 10.0.4 Build 729 - Unauthenticated Use-After-Free via Crafted SSH Identification String
CVSS 5.9
Thunderbird <60.7.1 - Use After Free
CVSS 7.5
Thunderbird <60.7.1 - Buffer Overflow
CVSS 9.8
Thunderbird <60.7.1 - Buffer Overflow
CVSS 9.8
Thunderbird <60.7.1 - Buffer Overflow
CVSS 9.8
Debian Linux < 4.1.0 - Memory Corruption
CVSS 9.8
Shadowsocks - Log File Command Execution
shadowsocks-libev 3.1.0 - Command Execution
Peplink Balance 305 380 580 710 1350 2500 Firmware - Arbitrary File Deletion via upfile.path Parameter
CVSS 8.1