Author: Angelo Barbosa

CVE-2024-30645 | Tenda AC15V1.0 15.03.20_multi /goform/setUsbUnload doSystemCmd deviceName command injection

A vulnerability, which was classified as critical, was found in Tenda AC15V1.0 15.03.20_multi. Affected is the function doSystemCmd of the file /goform/setUsbUnload. The manipulation of the argument deviceName leads to command injection. This vulnerability is traded as CVE-2024-30645. It is possible to launch the attack remotely. Furthermore, there is an exploit...

Read More

CVE-2023-49231 | Stilog Visual Planning 8 Administrative API Token improper authentication

A vulnerability, which was classified as critical, has been found in Stilog Visual Planning 8. This issue affects some unknown processing of the component Administrative API Token Handler. The manipulation leads to improper authentication. The identification of this vulnerability is CVE-2023-49231. The attack can only be done within the local network. There is no exploit...

Read More