CVE
Vendors
Products
Updated
CVSS v2
CVSS v3
Domoticz before 4.10578 allows SQL Injection via the idx parameter in CWebServer::GetFloorplanImage in WebServer.cpp.
Gac2500_firmware, Gac2500, Gvc3202_firmware, Gvc3202, Gxv3275_firmware, Gxv3275, Gxv3240_firmware, Gxv3240, Gxp2200_firmware, Gxp2200
2019-04-01
N/A
8.8 HIGH
Grandstream UCM6204 before 1.0.19.20 devices allow remote authenticated users to conduct SQL injection attacks via the sord parameter in a listCodeblueGroup API call to the /cgi? URI.
Gac2500_firmware, Gac2500, Gvc3202_firmware, Gvc3202, Gxv3275_firmware, Gxv3275, Gxv3240_firmware, Gxv3240, Gxp2200_firmware, Gxp2200
2020-08-24
N/A
8.8 HIGH
Grandstream UCM6204 before 1.0.19.20 devices allow remote authenticated users to execute arbitrary code via shell metacharacters in the backupUCMConfig file-backup parameter to the /cgi? URI.
Gac2500_firmware, Gac2500, Gvc3202_firmware, Gvc3202, Gxv3275_firmware, Gxv3275, Gxv3240_firmware, Gxv3240, Gxp2200_firmware, Gxp2200
2020-08-24
N/A
9.8 CRITICAL
On Grandstream GXV3611IR_HD before 1.0.3.23 devices, the root account lacks a password.
Gac2500_firmware, Gac2500, Gvc3202_firmware, Gvc3202, Gxv3275_firmware, Gxv3275, Gxv3240_firmware, Gxv3240, Gxp2200_firmware, Gxp2200
2020-08-24
N/A
8.8 HIGH
Grandstream GXV3611IR_HD before 1.0.3.23 devices allow remote authenticated users to execute arbitrary code via shell metacharacters in the /goform/systemlog?cmd=set logserver field.
** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2019. Notes: none.
Gac2500_firmware, Gac2500, Gvc3202_firmware, Gvc3202, Gxv3275_firmware, Gxv3275, Gxv3240_firmware, Gxv3240, Gxp2200_firmware, Gxp2200
2020-08-24
N/A
8.8 HIGH
Grandstream GXV3370 before 1.0.1.41 and WP820 before 1.0.3.6 devices allow remote authenticated users to execute arbitrary code via shell metacharacters in a /manager?action=getlogcat priority field.
Gac2500_firmware, Gac2500, Gvc3202_firmware, Gvc3202, Gxv3275_firmware, Gxv3275, Gxv3240_firmware, Gxv3240, Gxp2200_firmware, Gxp2200
2020-08-24
N/A
8.8 HIGH
Grandstream GWN7610 before 1.0.8.18 devices allow remote authenticated users to execute arbitrary code via shell metacharacters in the filename in a /ubus/controller.icc.update_nds_webroot_from_tmp update_nds_webroot_from_tmp API call.
Gac2500_firmware, Gac2500, Gvc3202_firmware, Gvc3202, Gxv3275_firmware, Gxv3275, Gxv3240_firmware, Gxv3240, Gxp2200_firmware, Gxp2200
2020-08-24
N/A
6.5 MEDIUM
Grandstream GWN7000 before 1.0.6.32 and GWN7610 before 1.0.8.18 devices allow remote authenticated users to discover passwords via a /ubus/uci.apply config request.
Gac2500_firmware, Gac2500, Gvc3202_firmware, Gvc3202, Gxv3275_firmware, Gxv3275, Gxv3240_firmware, Gxv3240, Gxp2200_firmware, Gxp2200
2020-08-24
N/A
8.8 HIGH
Grandstream GWN7000 before 1.0.6.32 devices allow remote authenticated users to execute arbitrary code via shell metacharacters in the filename in a /ubus/uci.apply update_nds_webroot_from_tmp API call.
