seiko-sol Vulnerabilities and Affected Products
Explore source-attributed vulnerabilities associated with seiko-sol products.
Products
- skybridge_mb-a200_firmware2 vulnerabilities
- skybridge_basic_mb-a130_firmware1 vulnerability
- skybridge_mb-a110_firmware1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2024-32850CRITICAL | Improper neutralization of special elements used in a command ('Command Injection') exists in SkyBridge MB-A100/MB-A110 firmware Ver. 4.2.2 and earlier and SkyBridge BASIC MB-A130 firmware Ver. 1.5.5 and earlier. If the remote monitoring and control function is enabled on the product, an attacker with access to the product may execute an arbitrary command or login to the product with the administrator privilege. CWE-78May 31, 2024 | CVSS9.8v3.1 | EPSS1.21% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2022-36560CRITICAL | seiko-sol skybridge_mb-a200_firmware Use of Hard-coded CredentialsSeiko SkyBridge MB-A200 v01.00.04 and below was discovered to contain multiple hard-coded passcodes for root. Attackers are able to access the passcodes at /etc/srapi/config/system.conf and /usr/sbin/ssol-sshd.sh. CWE-798Aug 29, 2022 | CVSS9.8v3.1 | EPSS0.707% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2022-36559CRITICAL | seiko-sol skybridge_mb-a200_firmware Improper Neutralization of Special Elements used in a Command ('Command Injection')Seiko SkyBridge MB-A200 v01.00.04 and below was discovered to contain a command injection vulnerability via the Ping parameter at ping_exec.cgi. CWE-77Aug 29, 2022 | CVSS9.8v3.1 | EPSS1.73% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |