CIRCUTOR TCP2RS+是CIRCUTOR公司的一个以太网转换器。 CIRCUTOR TCP2RS+ 1.3b版本存在输入验证错误漏洞,该漏洞源于允许攻击者在未经身份验证的情况下修改任何配置值,导致设备配置失效并使其无法使用。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
10-question deep dive: root cause, exploitation, mitigation, urgency. Read summary free, full version requires login.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| CIRCUTOR | CIRCUTOR TCP2RS+ | 1.3b | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2024-8887 | 10.0 CRITICAL | Authentication bypass vulnerability on CIRCUTOR Q-SMT |
| CVE-2024-8888 | 10.0 CRITICAL | Insufficient Session Expiration vulnerability on CIRCUTOR Q-SMT |
| CVE-2024-8890 | 8.0 HIGH | Insertion of Sensitive Information Into Sent Data vulnerability on CIRCUTOR Q-SMT |
| CVE-2024-8891 | 5.3 MEDIUM | Exposure of Private Personal Information to an Unauthorized Actor vulnerability on CIRCUTO |
| CVE-2024-8892 | 5.3 MEDIUM | Uncontrolled Resource Consumption vulnerability on CIRCUTOR TCP2RS+ |
No comments yet