Linear eMerge E3-Series devices allow Directory Traversal.
Linear eMerge E3-Series devices have Default Credentials.
An issue was discovered on D-Link DCS-1130 devices. The device provides a user with the capability of setting a SMB folder for the video clippings recorded by the device. It seems that the POST parameters passed in this request (to test if email credentials and hostname sent to the device work properly) result in being passed as commands to a "system" API in the function and thus result in command injection on the device. If the firmware version is dissected using binwalk tool, we obtain a cramf
Linear eMerge E3-Series devices have Hard-coded Credentials.
Linear eMerge E3-Series devices have Cleartext Credentials in a Database.
Linear eMerge 50P/5000P devices allow Authenticated Command Injection with root Code Execution.
Linear eMerge 50P/5000P devices allow Unauthenticated File Upload.
Linear eMerge 50P/5000P devices allow Cookie Path Traversal.
Linear eMerge 50P/5000P devices allow Authentication Bypass.
Linear eMerge E3-Series devices allow Remote Code Execution (root access over SSH).
Linear eMerge E3-Series devices allow a Stack-based Buffer Overflow on the ARM platform.
Linear eMerge E3-Series devices have a Version Control Failure.
DOSBox 0.74-2 has Incorrect Access Control.
An issue was discovered on D-Link DCS-1130 devices. The device provides a user with the capability of setting a SMB folder for the video clippings recorded by the device. It seems that the GET parameters passed in this request (to test if SMB credentials and hostname sent to the device work properly) result in being passed as commands to a "system" API in the function and thus result in command injection on the device. If the firmware version is dissected using binwalk tool, we obtain a cramfs-r
IBM Spectrum Protect Servers 7.1 and 8.1 and Storage Agents are vulnerable to a stack-based buffer overflow, caused by improper bounds checking by servers and storage agents in response to specifically crafted communication exchanges. By sending an overly long request, a remote attacker could overflow a buffer and execute arbitrary code on the system with instance id privileges or cause the server or storage agent to crash. IBM X-Force ID: 157510.
Optergy Proton/Enterprise devices allow Authenticated File Upload with Code Execution as root.
Nortek Linear eMerge 50P/5000P devices have Default Credentials.
NetApp AFF A700s Baseboard Management Controller (BMC) firmware versions 1.22 and higher were shipped with a default account enabled that could allow unauthorized arbitrary command execution.
SICK MSC800 all versions prior to Version 4.0, the affected firmware versions contain a hard-coded customer account password.