lukejenkins

2 exploits Active since Sep 2021
CVE-2022-24693 NOMISEC CRITICAL WRITEUP
Baicells Nova436Q & Neutrino 430 - Info Disclosure
Baicells Nova436Q and Neutrino 430 devices with firmware through QRTB 2.7.8 have hardcoded credentials that are easily discovered, and can be used by remote attackers to authenticate via ssh. (The credentials are stored in the firmware, encrypted by the crypt function.)
3 stars
CVSS 9.8
CVE-2021-34767 NOMISEC HIGH WRITEUP
Cisco IOS XE Wireless Controller Software - Unauthenticated Denial of Service via IPv6 Traffic Processing
A vulnerability in IPv6 traffic processing of Cisco IOS XE Wireless Controller Software for Cisco Catalyst 9000 Family Wireless Controllers could allow an unauthenticated, adjacent attacker to cause a Layer 2 (L2) loop in a configured VLAN, resulting in a denial of service (DoS) condition for that VLAN. The vulnerability is due to a logic error when processing specific link-local IPv6 traffic. An attacker could exploit this vulnerability by sending a crafted IPv6 packet that would flow inbound through the wired interface of an affected device. A successful exploit could allow the attacker to cause traffic drops in the affected VLAN, thus triggering the DoS condition.
CVSS 7.4