Helmholz REX100是Helmholz公司的一款无线路由器。 Helmholz REX100 2.3.1之前版本存在输入验证错误漏洞,该漏洞源于输入验证不当,未经身份验证的本地攻击者可以通过部署配置文件来获取管理员权限。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| MB connect line | mbNET.mini | 0.0.0 ~ 2.2.13 | - |
|
| Helmholz | REX100 | 0.0.0 ~ 2.2.13 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2024-45274 | 9.8 CRITICAL | MB connect line/Helmholz: Remote code execution via confnet service |
| CVE-2024-45275 | 9.8 CRITICAL | MB connect line/Helmholz: Hardcoded user accounts with hard-coded passwords |
| CVE-2024-45273 | 8.4 HIGH | MB connect line/Helmholz: Weak encryption of configuration file |
| CVE-2024-45272 | 7.5 HIGH | MB connect line/Helmholz: Generation of weak passwords vulnerability |
| CVE-2024-45276 | 7.5 HIGH | MB connect line/Helmholz: tmp directory exposed via webservice |
No comments yet