CWE-494

Medium likelihood

Download of Code Without Integrity Check

Parent: CWE-345 - Insufficient Verification of Data Authenticity

The product downloads source code or an executable from a remote location and executes the code without sufficiently verifying the origin and integrity of the code.

204 vulnerabilities with CWE-494
CVE-2025-55581 HIGH
D-Link DCS-825L <1.08.01 - Code Injection
CVSS 7.3
CVE-2025-31355 HIGH
Tenda AC6 Firmware V02.03.01.110 - Arbitrary Code Execution via Malicious Firmware Update
CVSS 7.2
CVE-2025-53520 HIGH
EG4 Electronics EG4 12kPV, 18kPV, Flex 21, Flex 18, 6000XP, 12000XP, GridBoss - Unauthenticated Firmware Tampering
CVSS 8.8
CVE-2025-53696 CRITICAL
iSTAR Ultra < 6.9.2 - Unauthenticated Firmware Integrity Bypass
CVE-2025-7620 HIGH
Digitware Cross-Browser Document Creation Component - Drive-By Code Execution
CVSS 8.8
CVE-2025-52937 LOW
PointCloudLibrary PCL <1.14.0 - Buffer Overflow
CVE-2025-28236 CRITICAL
Nautel VX Series transmitters <6.4.0 - RCE
CVSS 9.8
CVE-2025-27593 CRITICAL
SDD Device Drivers - Code Injection
CVSS 9.3
CVE-2025-1058 HIGH
Schneider Electric ASCO 5310 and 5350 - Download of Code Without Integrity Check
CVSS 8.1
CVE-2024-47192 MEDIUM
Mahara < 23.04.9 - Unauthenticated Arbitrary File Download via Export URL
CVSS 5.3
CVE-2024-43169 HIGH
IBM Engineering Requirements Management DOORS Next <7.1 - Info Disc...
CVSS 8.8
CVE-2024-50696 HIGH
SunGrow WiNet-S Firmware < 200.001.00.P025 - Unauthenticated Firmware Update via MQTT Message
CVSS 7.5
CVE-2024-52331 HIGH
ECOVACS Robot Lawnmowers and Vacuums - Arbitrary Firmware Installation via Deterministic Symmetric Key
CVSS 7.5
CVE-2024-42183 LOW
BigFix Patch Download Plug-ins - File Download
CVSS 2.5
CVE-2024-55459 MEDIUM
Keras 3.7.0 - Arbitrary File Write via get_file Tar Download
CVSS 6.5
CVE-2024-54126 HIGH
TP-Link Archer C50 < V4_240917 Authenticated Firmware Signature Bypass
CVE-2024-52583 HIGH
WesHacks - Malicious JavaScript Injection via Leostop Dependency
CVSS 8.2
CVE-2024-48974 CRITICAL
Baxter Life2000 Ventilation System < 06.08.00.00 - Unauthorized Firmware Modification via Missing Integrity Check
CVSS 9.3
CVE-2024-33660 MEDIUM
AMI Aptio V 5.0-5.037 - Unauthenticated Download of Code Without Integrity Check
CVSS 4.3
CVE-2024-45321 HIGH
App::cpanminus <1.7047 - Code Injection
CVSS 8.1
CVE-2024-39819 MEDIUM
Zoom Meeting SDK <6.0.10, Rooms <5.17.13, Workplace Desktop <6.0.10 - Privilege Escalation via Installer Bypass
CVSS 6.7
CVE-2024-39348 HIGH
Synology Router Manager < 1.2.5-8227 - Remote Code Execution via AirPrint Functionality
CVSS 7.5
CVE-2024-30206 HIGH
SIMATIC RTLS Locating Manager -<V3.0.1.1 - Info Disclosure
CVSS 8.8
CVE-2024-33118 HIGH
LuckyFrameWeb 3.5.2 - Arbitrary File Read via fileDownload Method
CVSS 7.5
CVE-2024-28878 CRITICAL
IOSiX IO-1020 Micro ELD < 360 - Unauthenticated Code Execution via Unverified Download
CVSS 9.6
Details
Vulnerabilities 204
Exploit Likelihood Medium