Vulnerabilities (CVE)

Filtered by vendor Wayos Subscribe
Total 4 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2023-37794 1 Wayos 2 Fbm-291w, Fbm-291w Firmware 2024-11-21 N/A 9.8 CRITICAL
WAYOS FBM-291W 19.09.11V was discovered to contain a command injection vulnerability via the component /upgrade_filter.asp.
CVE-2023-37793 1 Wayos 2 Fbm-291w, Fbm-291w Firmware 2024-11-21 N/A 9.8 CRITICAL
WAYOS FBM-291W 19.09.11V was discovered to contain a buffer overflow via the component /upgrade_filter.asp.
CVE-2022-41489 1 Wayos 12 Lq-04, Lq-04 Firmware, Lq-05 and 9 more 2024-11-21 N/A 8.1 HIGH
WAYOS LQ_09 22.03.17V was discovered to contain a Cross-Site Request Forgery (CSRF) which allows attackers to send crafted requests to the server from the affected device. This vulnerability is exploitable due to a lack of authentication in the component Usb_upload.htm.
CVE-2024-44383 1 Wayos 2 Fbm-291w, Fbm-291w Firmware 2024-09-05 N/A 6.8 MEDIUM
WAYOS FBM-291W v19.09.11 is vulnerable to Command Execution via msp_info_htm.