All CVEs — page 29 of 242
The complete archive, 25 per page, newest first. 6034 records. Search instead.
The flaw allows unauthenticated attackers to reset any storefront account password through the PUT /user/updatePwd endpoint, enabling account takeover and access to sensitive data.
The vulnerability allows command injection through the password1 argument in the /api/ZRnetwork/set_passwd endpoint, enabling remote attackers to execute arbitrary commands.
A command injection vulnerability exists in Ziroom ZHOME A0101 1.0.1.0, allowing remote attackers to execute arbitrary commands via the mac argument.
The vulnerability allows command injection through the manipulation of the 'ip' argument, enabling remote attackers to execute arbitrary commands on the server.
The flaw allows command injection via manipulation of the login_pwd argument in the /api/ZRnetwork/firstSetup_wifi endpoint, enabling remote attackers to execute arbitrary commands.