Hidglobal
Hidglobal Ep4502 Firmware: vulnerabilidades y CVE
Hidglobal Ep4502 Firmware tiene 8 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 2 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE8
Últimos 12 meses0
Críticas2
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2022-31486 | Alta (8.8) | 1.3% | — | 6 jun 2022 | An authenticated attacker can send a specially crafted route to the “edit_route.cgi” binary and have it execute shell commands. This vulnerability impacts products based on HID Mercury Intelligent Controllers LP1501,… |
| CVE-2022-31485 | Media (5.3) | 0.81% | — | 6 jun 2022 | An unauthenticated attacker can send a specially crafted packets to update the “notes” section of the home page of the web interface. This vulnerability impacts products based on HID Mercury Intelligent Controllers… |
| CVE-2022-31484 | Alta (7.5) | 1.0% | — | 6 jun 2022 | An unauthenticated attacker can send a specially crafted network packet to delete a user from the web interface. This vulnerability impacts products based on HID Mercury Intelligent Controllers LP1501, LP1502, LP2500,… |
| CVE-2022-31483 | Alta (8.8) | 1.8% | — | 6 jun 2022 | An authenticated attacker can upload a file with a filename including “..” and “/” to achieve the ability to upload the desired file anywhere on the filesystem. This vulnerability impacts products based on HID Mercury… |
| CVE-2022-31482 | Alta (7.5) | 1.0% | — | 6 jun 2022 | An unauthenticated attacker can send a specially crafted unauthenticated HTTP request to the device that can overflow a buffer. This vulnerability impacts products based on HID Mercury Intelligent Controllers LP1501,… |
| CVE-2022-31481 | Crítica (10) | 1.5% | — | 6 jun 2022 | An unauthenticated attacker can send a specially crafted update file to the device that can overflow a buffer. This vulnerability impacts products based on HID Mercury Intelligent Controllers LP1501, LP1502, LP2500,… |
| CVE-2022-31480 | Alta (7.5) | 0.94% | — | 6 jun 2022 | An unauthenticated attacker could arbitrarily upload firmware files to the target device, ultimately causing a Denial-of-Service (DoS). This vulnerability impacts products based on HID Mercury Intelligent Controllers… |
| CVE-2022-31479 | Crítica (9.8) | 2.4% | — | 6 jun 2022 | An unauthenticated attacker can update the hostname with a specially crafted name that will allow for shell commands to be executed during the core collection process. This vulnerability impacts products based on HID… |