Helmholz REX100是Helmholz公司的一款无线路由器。 Helmholz REX100 2.3.1之前版本存在信任管理问题漏洞,该漏洞源于包含两个硬编码的用户帐户和硬编码的密码,允许未经身份验证的远程攻击者完全控制受影响的设备。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
10-question deep dive: root cause, exploitation, mitigation, urgency. Read summary free, full version requires login.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| MB connect line | mbNET.mini | 0.0.0 ~ 2.2.13 | - |
|
| Helmholz | REX100 | 0.0.0 ~ 2.2.13 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2024-45274 | 9.8 CRITICAL | MB connect line/Helmholz: Remote code execution via confnet service |
| CVE-2024-45273 | 8.4 HIGH | MB connect line/Helmholz: Weak encryption of configuration file |
| CVE-2024-45271 | 8.4 HIGH | MB connect line/Helmholz: Remote code execution due to improper input validation |
| CVE-2024-45272 | 7.5 HIGH | MB connect line/Helmholz: Generation of weak passwords vulnerability |
| CVE-2024-45276 | 7.5 HIGH | MB connect line/Helmholz: tmp directory exposed via webservice |
No comments yet