CISA Adds Five Known Exploited Vulnerabilities to Catalog | CISA (06/02)
『CISA added five new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation.
- CVE-2021-32030 ASUS Routers Improper Authentication Vulnerability
『The administrator application on ASUS GT-AC2900 devices before 3.0.0.4.386.42643 and Lyra Mini before 3.0.0.4_384_46630 allows authentication bypass when processing remote input from an unauthenticated user, leading to unauthorized access to the administrator interface. This relates to handle_request in router/httpd/httpd.c and auth_check in web_hook.o. An attacker-supplied value of '\0' matches the device's default value of '\0' in some situations.
…
3.0.0.4.386.42643より前のASUS GT-AC2900デバイスおよび3.0.0.4_384_
- CVE-2023-39780 ASUS RT-AX55 Routers OS Command Injection Vulnerability
『On ASUS RT-AX55 3.0.0.4.386.51598 devices, authenticated attackers can perform OS command injection via the /start_apply.htm qos_bw_rulelist parameter.
…
ASUS RT-AX55 3.0.0.4.386.51598デバイスでは、
- CVE-2024-56145 Craft CMS Code Injection Vulnerability
- CVE-2025-3935 ConnectWise ScreenConnect Improper Authentication Vulnerability
- CVE-2025-35939 Craft CMS External Control of Assumed-Immutable Web Parameter Vulnerability
』
No comments:
Post a Comment