Vulnerabilities (CVE)

Filtered by vendor Securifi
Filtered by product Almond\+
Angry Yack Logo
Total 10 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2017-8337 1 Securifi 6 Almond, Almond\+, Almond\+firmware and 3 more 2024-11-21 6.8 MEDIUM 8.8 HIGH
An issue was discovered on Securifi Almond, Almond+, and Almond 2015 devices with firmware AL-R096. The device provides a user with the capability of executing various actions on the web management interface. It seems that the device does not implement any Origin header check which allows an attacker who can trick a user to navigate to an attacker's webpage to exploit this issue and brute force the password for the web management interface. It also allows an attacker to then execute any other ac ...

Show More

CVE-2017-8336 1 Securifi 6 Almond, Almond\+, Almond\+firmware and 3 more 2024-11-21 6.5 MEDIUM 8.8 HIGH
An issue was discovered on Securifi Almond, Almond+, and Almond 2015 devices with firmware AL-R096. The device provides a user with the capability of adding new routes to the device. It seems that the POST parameters passed in this request to set up routes on the device can be set in such a way that would result in overflowing the stack set up and allow an attacker to control the $ra register stored on the stack. If the firmware version AL-R096 is dissected using binwalk tool, we obtain a cpio-r ...

Show More

CVE-2017-8335 1 Securifi 6 Almond, Almond\+, Almond\+firmware and 3 more 2024-11-21 6.0 MEDIUM 8.0 HIGH
An issue was discovered on Securifi Almond, Almond+, and Almond 2015 devices with firmware AL-R096. The device provides a user with the capability of setting name for wireless network. These values are stored by the device in NVRAM (Non-volatile RAM). It seems that the POST parameters passed in this request to set up names on the device do not have a string length check on them. This allows an attacker to send a large payload in the "mssid_1" POST parameter. The device also allows a user to view ...

Show More

CVE-2017-8334 1 Securifi 6 Almond, Almond\+, Almond\+firmware and 3 more 2024-11-21 6.0 MEDIUM 8.0 HIGH
An issue was discovered on Securifi Almond, Almond+, and Almond 2015 devices with firmware AL-R096. The device provides a user with the capability of blocking IP addresses using the web management interface. It seems that the device does not implement any cross-site scripting forgery protection mechanism which allows an attacker to trick a user who is logged in to the web management interface into executing a cross-site scripting payload on the user's browser and execute any action on the device ...

Show More

CVE-2017-8333 1 Securifi 6 Almond, Almond\+, Almond\+firmware and 3 more 2024-11-21 9.0 HIGH 8.8 HIGH
An issue was discovered on Securifi Almond, Almond+, and Almond 2015 devices with firmware AL-R096. The device provides a user with the capability of adding new routes to the device. It seems that the POST parameters passed in this request to set up routes on the device can be set in such a way that would result in passing commands to a "popen" API in the function and thus result in command injection on the device. If the firmware version AL-R096 is dissected using binwalk tool, we obtain a cpio ...

Show More

CVE-2017-8332 1 Securifi 6 Almond, Almond\+, Almond\+firmware and 3 more 2024-11-21 6.5 MEDIUM 8.8 HIGH
An issue was discovered on Securifi Almond, Almond+, and Almond 2015 devices with firmware AL-R096. The device provides a user with the capability of blocking key words passing in the web traffic to prevent kids from watching content that might be deemed unsafe using the web management interface. It seems that the device does not implement any cross-site scripting protection mechanism which allows an attacker to trick a user who is logged in to the web management interface into executing a store ...

Show More

CVE-2017-8331 1 Securifi 6 Almond, Almond\+, Almond\+firmware and 3 more 2024-11-21 6.5 MEDIUM 8.8 HIGH
An issue was discovered on Securifi Almond, Almond+, and Almond 2015 devices with firmware AL-R096. The device provides a user with the capability of adding new port forwarding rules to the device. It seems that the POST parameters passed in this request to set up routes on the device can be set in such a way that would result in passing commands to a "system" API in the function and thus result in command injection on the device. If the firmware version AL-R096 is dissected using binwalk tool, ...

Show More

CVE-2017-8330 1 Securifi 6 Almond, Almond\+, Almond\+firmware and 3 more 2024-11-21 3.3 LOW 6.5 MEDIUM
An issue was discovered on Securifi Almond, Almond+, and Almond 2015 devices with firmware AL-R096. The device provides a UPnP functionality for devices to interface with the router and interact with the device. It seems that the "NewInMessage" SOAP parameter passed with a huge payload results in crashing the process. If the firmware version AL-R096 is dissected using binwalk tool, we obtain a cpio-root archive which contains the filesystem set up on the device that contains all the binaries. Th ...

Show More

CVE-2017-8329 1 Securifi 6 Almond, Almond\+, Almond\+firmware and 3 more 2024-11-21 4.6 MEDIUM 6.4 MEDIUM
An issue was discovered on Securifi Almond, Almond+, and Almond 2015 devices with firmware AL-R096. The device provides a user with the capability of setting a name for the wireless network. These values are stored by the device in NVRAM (Non-volatile RAM). It seems that the POST parameters passed in this request to set up names on the device do not have a string length check on them. This allows an attacker to send a large payload in the "mssid_1" POST parameter. The device also allows a user t ...

Show More

CVE-2017-8328 1 Securifi 6 Almond, Almond\+, Almond\+firmware and 3 more 2024-11-21 9.3 HIGH 8.8 HIGH
An issue was discovered on Securifi Almond, Almond+, and Almond 2015 devices with firmware AL-R096. The device provides a user with the capability of changing the administrative password for the web management interface. It seems that the device does not implement any cross site request forgery protection mechanism which allows an attacker to trick a user who is logged in to the web management interface to change a user's password. Also this is a systemic issue.