cbcvebase.

Helmholz Rex 100 Firmware vulnerabilities

5 known vulnerabilities affecting helmholz/rex_100_firmware.

Total CVEs
5
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL2HIGH3

Vulnerabilities

Page 1 of 1
CVE-2024-45274P2CRITICALCVSS 9.8fixed in 2.3.12024-10-15
CVE-2024-45274 [CRITICAL] CWE-306 CVE-2024-45274: An unauthenticated remote attacker can execute OS commands via UDP on the device due to missing auth An unauthenticated remote attacker can execute OS commands via UDP on the device due to missing authentication.
nvd
CVE-2024-45275P2CRITICALCVSS 9.8fixed in 2.3.12024-10-15
CVE-2024-45275 [CRITICAL] CWE-798 CVE-2024-45275: The devices contain two hard coded user accounts with hardcoded passwords that allow an unauthentica The devices contain two hard coded user accounts with hardcoded passwords that allow an unauthenticated remote attacker for full control of the affected devices.
nvd
CVE-2024-45276P3HIGHCVSS 7.5fixed in 2.3.12024-10-15
CVE-2024-45276 [HIGH] CWE-306 CVE-2024-45276: An unauthenticated remote attacker can get read access to files in the "/tmp" directory due to missi An unauthenticated remote attacker can get read access to files in the "/tmp" directory due to missing authentication.
nvd
CVE-2024-45271P3HIGHCVSS 7.8fixed in 2.3.12024-10-15
CVE-2024-45271 [HIGH] CWE-94 CVE-2024-45271: An unauthenticated local attacker can gain admin privileges by deploying a config file due to improp An unauthenticated local attacker can gain admin privileges by deploying a config file due to improper input validation.
nvd
CVE-2024-45273P3HIGHCVSS 7.8fixed in 2.3.12024-10-15
CVE-2024-45273 [HIGH] CWE-261 CVE-2024-45273: An unauthenticated local attacker can decrypt the devices config file and therefore compromise the d An unauthenticated local attacker can decrypt the devices config file and therefore compromise the device due to a weak implementation of the encryption used.
nvd
Helmholz Rex 100 Firmware vulnerabilities | cvebase