funny-mud-peee
18 exploits
Active since Jan 2024
TOTOLINK A8000RU v7.1cu.643_B20200521 - Use of Hard-coded Credentials
CVSS 9.8
TOTOLINK A3300R V17.0.0cu.557_B20221024 - OS Command Injection via setParentalRules enable Parameter
CVSS 9.8
TOTOLINK A3300R V17.0.0cu.557_B20221024 - OS Command Injection via arpEnable Parameter
CVSS 9.8
TOTOLINK A3300R V17.0.0cu.557_B20221024 - OS Command Injection via pppoePass Parameter
CVSS 9.8
TotoLink Router setMacFilterRules - Command Injection
CVSS 9.8
TotoLink Router setPortForwardRules - Command Injection
CVSS 9.8
TOTOLINK A3300R V17.0.0cu.557_B20221024 - OS Command Injection via setRemoteCfg Port or Enable Parameter
CVSS 9.8
TOTOLINK A3300R V17.0.0cu.557_B20221024 - OS Command Injection via setWiFiScheduleCfg enable Parameter
CVSS 9.8
TOTOLINK A3300R V17.0.0cu.557_B20221024 - OS Command Injection via setUrlFilterRules URL Parameter
CVSS 9.8
TOTOLINK A3300R V17.0.0cu.557_B20221024 - OS Command Injection via setWiFiAclRules desc Parameter
CVSS 9.8
TOTOLINK A8000RU V7.1cu.643_B20200521 - Unauthenticated Login Bypass via Session Cookie
CVSS 8.0
Netgear CBR40, CBK40, CBK43 2.5.0.28 - Unauthenticated Sensitive Information Exposure via debuginfo.htm
CVSS 5.4
Netgear CBR40, CBK40, CBK43 2.5.0.28 - Unauthenticated Sensitive Information Exposure via currentsetting.htm
CVSS 7.5
Netgear R6850 1.1.0.88 - OS Command Injection via c4-IPAddr Parameter
CVSS 9.8
Netgear R6850 v1.1.0.88 - Unauthenticated Exposure of Sensitive Information via currentsetting.htm
CVSS 7.5
Netgear R6850 v1.1.0.88 - Unauthenticated Sensitive Information Exposure via debuginfo.htm
CVSS 5.3
Netgear R6850 v1.1.0.88 - Unauthenticated Exposure of Sensitive Information in BRS_top.html
CVSS 7.5
Netgear R6850 1.1.0.88 - OS Command Injection via ntp_server Parameter
CVSS 8.0