Showing 3 vulnerabilities on this page for UD-LT1/EX

Signals CISA KEV Ransomware Nuclei
I-O DATA DEVICE, INC. vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

UD-LT1 and UD-LT1/EX Firmware Arbitrary OS Command Execution

Inclusion of undocumented features or chicken bits issue exists in UD-LT1 firmware Ver.2.1.8 and earlier and UD-LT1/EX firmware Ver.2.1.8 and earlier. A remote attacker may disable the firewall function of the affected products. As a result, an arbitrary OS command may be executed and/or configuration settings of the device may be altered.

CWE-1242Dec 5, 2024
CVSS7.5v3.0EPSS0.58%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

UD-LT1 and UD-LT1/EX Firmware Admin Account Arbitrary OS Command Execution

UD-LT1 firmware Ver.2.1.9 and earlier and UD-LT1/EX firmware Ver.2.1.9 and earlier allow a remote authenticated attacker with an administrative account to execute arbitrary OS commands.

CWE-78Dec 5, 2024
CVSS7.2v3.0EPSS0.904%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

UD-LT1 and UD-LT1/EX Firmware Guest Account Credential Disclosure

Incorrect permission assignment for critical resource issue exists in UD-LT1 firmware Ver.2.1.9 and earlier and UD-LT1/EX firmware Ver.2.1.9 and earlier. If an attacker with the guest account of the affected products accesses a specific file, the information containing credentials may be obtained.

CWE-732Dec 5, 2024
CVSS6.5v3.0EPSS0.483%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX