Sapido Gr297N Firmware vulnerabilities

3 known vulnerabilities affecting sapido/gr297n_firmware.

Total CVEs
3
CISA KEV
0
Public exploits
2
Exploited in wild
0
Severity breakdown
HIGH3

Vulnerabilities

Page 1 of 1
CVE-2021-4242HIGHCVSS 8.8v2.1.32022-11-30
CVE-2021-4242 [HIGH] CWE-707 CVE-2021-4242: A vulnerability was found in Sapido BR270n, BRC76n, GR297 and RB1732 and classified as critical. Aff A vulnerability was found in Sapido BR270n, BRC76n, GR297 and RB1732 and classified as critical. Affected by this issue is some unknown functionality of the file ip/syscmd.htm. The manipulation leads to os command injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerab
nvd
CVE-2019-19823HIGHCVSS 7.5PoC≤ 2019-12-122020-01-27
CVE-2019-19823 [HIGH] CWE-522 CVE-2019-19823: A certain router administration interface (that includes Realtek APMIB 0.11f for Boa 0.94.14rc21) st A certain router administration interface (that includes Realtek APMIB 0.11f for Boa 0.94.14rc21) stores cleartext administrative passwords in flash memory and in a file. This affects TOTOLINK A3002RU through 2.0.0, A702R through 2.1.3, N301RT through 2.1.6, N302R through 3.4.0, N300RT through 3.4.0, N200RE through 4.0.0, N150RT through 3.4.0, and N10
nvd
CVE-2019-19822HIGHCVSS 7.5PoC≤ 2019-12-122020-01-27
CVE-2019-19822 [HIGH] CWE-306 CVE-2019-19822: A certain router administration interface (that includes Realtek APMIB 0.11f for Boa 0.94.14rc21) al A certain router administration interface (that includes Realtek APMIB 0.11f for Boa 0.94.14rc21) allows remote attackers to retrieve the configuration, including sensitive data (usernames and passwords). This affects TOTOLINK A3002RU through 2.0.0, A702R through 2.1.3, N301RT through 2.1.6, N302R through 3.4.0, N300RT through 3.4.0, N200RE through 4.
nvd