Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
10-question deep dive: root cause, exploitation, mitigation, urgency. Read summary free, full version requires login.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | n/a | n/a | - |
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | NETGEAR ProSAFE Plus before 2.6.0.43 is susceptible to unauthenticated remote code execution. Any HTML page is allowed as a valid endpoint to submit POST requests, allowing debug action via the submitId and debugCmd parameters. The problem is publicly exposed in the login.html webpage, which has to be publicly available to perform login requests but does not implement any restriction for executing debug actions. This will allow attackers to execute system commands. | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2020/CVE-2020-26919.yaml | POC Details |
No public POC found.
Login to generate AI POC| CVE-2020-26928 | 9.6 CRITICAL | 多款 NETGEAR 产品授权问题漏洞 |
| CVE-2020-26907 | 9.6 CRITICAL | 多款 NETGEAR 产品命令注入漏洞 |
| CVE-2020-26906 | 9.6 CRITICAL | 多款 NETGEAR 设备安全漏洞 |
| CVE-2020-26905 | 9.6 CRITICAL | 多款 NETGEAR 设备安全漏洞 |
| CVE-2020-26904 | 9.6 CRITICAL | 多款 NETGEAR 设备安全漏洞 |
| CVE-2020-26903 | 9.6 CRITICAL | 多款 NETGEAR 设备安全漏洞 |
| CVE-2020-26902 | 9.6 CRITICAL | 多款 NETGEAR 设备命令注入漏洞 |
| CVE-2020-26901 | 9.6 CRITICAL | 多款 NETGEAR 设备信息泄露漏洞 |
| CVE-2020-26900 | 9.6 CRITICAL | 多款 NETGEAR 设备安全漏洞 |
| CVE-2020-26899 | 9.6 CRITICAL | 多款 NETGEAR 设备信息泄露漏洞 |
| CVE-2020-26898 | 9.6 CRITICAL | NETGEAR RAX40 安全漏洞 |
| CVE-2020-26897 | 9.6 CRITICAL | NETGEAR RBR750 安全漏洞 |
| CVE-2020-26926 | 9.6 CRITICAL | 多款 NETGEAR 产品授权问题漏洞 |
| CVE-2020-26927 | 9.4 CRITICAL | 多款 NETGEAR 产品授权问题漏洞 |
| CVE-2020-26908 | 9.4 CRITICAL | 多款 NETGEAR 设备安全漏洞 |
| CVE-2020-26920 | 8.8 HIGH | 多款 NETGEAR 设备命令注入漏洞 |
| CVE-2020-26909 | 8.8 HIGH | 多款 NETGEAR 设备命令注入漏洞 |
| CVE-2020-26910 | 8.4 HIGH | 多款 NETGEAR 产品命令注入漏洞 |
| CVE-2020-26911 | 8.3 HIGH | 多款 NETGEAR 设备安全漏洞 |
| CVE-2020-26921 | 8.3 HIGH | 多款 NETGEAR 设备安全漏洞 |
Showing top 20 of 41 CVEs. View all on vendor page → →
No comments yet