Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3027▼ 69 respecto a la semana anterior
Críticas / altas1424▲ 58 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
6 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 0.31% | — | Chcnav P5E Gnss Firmware | 18/7/2022 | 17/6/2026 | This vulnerability affects all of the company's products that also include the FW versions: update_i90_cv2.021_b20210104, update_i50_v1.0.55_b20200509, update_x6_v2.1.2_b202001127, update_b5_v2.0.9_b20200706. This vulnerability makes it possible to extract from the FW the existing user passwords on their operating… | |
| Modificada | Alta (7.5) | 0.23% | — | Chcnav P5E Gnss Firmware | 18/7/2022 | 17/6/2026 | Browsing the path: http://ip/wifi_ap_pata_get.cmd, will show in the name of the existing access point on the component, and a password in clear text. | |
| Modificada | Media (5.3) | 0.34% | — | Chcnav P5E Gnss Firmware | 18/7/2022 | 17/6/2026 | Directory listing is a web server function that displays the directory contents when there is no index file in a specific website directory. A directory listing provides an attacker with the complete index of all the resources located inside of the directory. The specific risks and consequences vary depending on which… | |
| Modificada | Alta (7.5) | 0.34% | — | Chcnav P5E Gnss Firmware | 18/7/2022 | 17/6/2026 | Browsing the admin.html page allows the user to reset the admin password. Also appears in the JS code for the password. | |
| Modificada | Crítica (9.8) | 0.42% | — | Chcnav P5E Gnss Firmware | 18/7/2022 | 17/6/2026 | The server checks the user's cookie in a non-standard way, and a value is entered in the cookie value name of the status and its value is set to true to bypass the identification with the system using a username and password. | |
| Modificada | Alta (7.3) | 0.18% | — | Chcnav P5E Gnss Firmware | 17/7/2022 | 17/6/2026 | Disclosure of information - the system allows you to view usernames and passwords without permissions, thus it will be possible to enter the system. Path access: http://api/sys_username_passwd.cmd - The server loads the request clearly by default. Disclosure of hard-coded credit information within the JS code sent to… |