Seiko-Sol Skybridge Mb-A200 Firmware vulnerabilities
6 known vulnerabilities affecting seiko-sol/skybridge_mb-a200_firmware.
Total CVEs
6
CISA KEV
0
Public exploits
0
Exploited in wild
2
Severity breakdown
CRITICAL2HIGH3MEDIUM1
Vulnerabilities
Page 1 of 1
CVE-2022-36559P1CRITICALCVSS 9.8Exploited≤ 01.00.042022-08-29
CVE-2022-36559 [CRITICAL] CWE-77 CVE-2022-36559: Seiko SkyBridge MB-A200 v01.00.04 and below was discovered to contain a command injection vulnerabil
Seiko SkyBridge MB-A200 v01.00.04 and below was discovered to contain a command injection vulnerability via the Ping parameter at ping_exec.cgi.
nvd
CVE-2022-36560P2CRITICALCVSS 9.8Exploited≤ 01.00.042022-08-29
CVE-2022-36560 [CRITICAL] CWE-798 CVE-2022-36560: Seiko SkyBridge MB-A200 v01.00.04 and below was discovered to contain multiple hard-coded passcodes
Seiko SkyBridge MB-A200 v01.00.04 and below was discovered to contain multiple hard-coded passcodes for root. Attackers are able to access the passcodes at /etc/srapi/config/system.conf and /usr/sbin/ssol-sshd.sh.
nvd
CVE-2023-22441P3HIGHCVSS 8.6≤ 01.00.052023-05-10
CVE-2023-22441 [HIGH] CWE-306 CVE-2023-22441: Missing authentication for critical function exists in Seiko Solutions SkyBridge series, which may a
Missing authentication for critical function exists in Seiko Solutions SkyBridge series, which may allow a remote attacker to obtain or alter the setting information of the product or execute some critical functions without authentication, e.g., rebooting the product. Affected products and versions are as follows: SkyBridge MB-A200 firmware Ver. 01.00
nvd
CVE-2023-23578P3HIGHCVSS 7.5≤ 01.00.052023-05-10
CVE-2023-23578 [HIGH] CWE-346 CVE-2023-23578: Improper access control vulnerability in SkyBridge MB-A200 firmware Ver. 01.00.05 and earlier allows
Improper access control vulnerability in SkyBridge MB-A200 firmware Ver. 01.00.05 and earlier allows a remote unauthenticated attacker to connect to the product's ADB port.
nvd
CVE-2023-25184P3HIGHCVSS 7.5≤ 01.00.052023-05-10
CVE-2023-25184 [HIGH] CWE-521 CVE-2023-25184: Use of weak credentials exists in Seiko Solutions SkyBridge and SkySpider series, which may allow a
Use of weak credentials exists in Seiko Solutions SkyBridge and SkySpider series, which may allow a remote unauthenticated attacker to decrypt password for the WebUI of the product. Affected products and versions are as follows: SkyBridge MB-A200 firmware Ver. 01.00.05 and earlier, SkyBridge BASIC MB-A130 firmware Ver. 1.4.1 and earlier, and SkySpider
nvd
CVE-2023-23901P3MEDIUMCVSS 6.5≤ 01.00.052023-05-10
CVE-2023-23901 [MEDIUM] CWE-295 CVE-2023-23901: Improper following of a certificate's chain of trust exists in SkyBridge MB-A200 firmware Ver. 01.00
Improper following of a certificate's chain of trust exists in SkyBridge MB-A200 firmware Ver. 01.00.05 and earlier, and SkyBridge BASIC MB-A130 firmware Ver. 1.4.1 and earlier, which may allow a remote unauthenticated attacker to eavesdrop on or alter the communication sent to the WebUI of the product.
nvd