Genexis Vulnerabilities and Affected Products
Explore source-attributed vulnerabilities associated with Genexis products.
Products
- Tilgin Home Gateway2 vulnerabilities
- Platinum-44101 vulnerability
- platinum_4410_firmware1 vulnerability
- Tilgin Fiber Home Gateway HG15221 vulnerability
- tilgin_fiber_home_gateway_hg15221 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2021-47858MEDIUM | Genexis Platinum-4410 P4410-V2-1.31A - 'start_addr' Persistent Cross-Site ScriptingGenexis Platinum-4410 P4410-V2-1.31A contains a stored cross-site scripting vulnerability in the 'start_addr' parameter of the Security Management interface. Attackers can inject malicious scripts through the start source address field that will persist and trigger for privileged users when they access the security management page. CWE-79Jan 21, 2026 | CVSS5.1v4.0 | EPSS0.238% | PoCs1 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-8022MEDIUM | Genexis Tilgin Home Gateway cross site scriptingA vulnerability was found in Genexis Tilgin Home Gateway 322_AS0500-03_05_13_05. It has been rated as problematic. This issue affects some unknown processing of the file /vood/cgi-bin/vood_view.cgi?lang=EN&act=user/spec_conf&sessionId=86213915328111654515&user=A&message2user=Account%20updated. The manipulation of the argument Phone Number leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. NOTE: The vendor was contact… CWE-79Aug 20, 2024 | CVSS5.3v4.0 | EPSS0.358% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-6355MEDIUM | Genexis Tilgin Fiber Home Gateway HG1522 cross site scriptingA vulnerability was found in Genexis Tilgin Fiber Home Gateway HG1522 CSx000-01_09_01_12. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /status/product_info/. The manipulation of the argument product_info leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-269755. NOTE: The vendor was contacted early abo… CWE-79Jun 26, 2024 | CVSS6.9v4.0 | EPSS0.428% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-6108MEDIUM | Genexis Tilgin Home Gateway Login cross site scriptingA vulnerability was found in Genexis Tilgin Home Gateway 322_AS0500-03_05_13_05. It has been classified as problematic. Affected is an unknown function of the file /vood/cgi-bin/vood_view.cgi?act=index&lang=EN# of the component Login. The manipulation of the argument errmsg leads to basic cross site scripting. It is possible to launch the attack remotely. VDB-268854 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in… CWE-80Jun 18, 2024 | CVSS6.9v4.0 | EPSS0.428% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2021-29003CRITICAL | genexis platinum_4410_firmware Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')Genexis PLATINUM 4410 2.1 P4410-V2-1.28 devices allow remote attackers to execute arbitrary code via shell metacharacters to sys_config_valid.xgi, as demonstrated by the sys_config_valid.xgi?exeshell=%60telnetd%20%26%60 URI. CWE-78Apr 13, 2021 | CVSS9.8v3.1 | EPSS45.4% | PoCs2 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |