Vulnerabilities (CVE)

Filtered by vendor Planex Subscribe
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2017-12573 1 Planex 2 Cs-w50hd, Cs-w50hd Firmware 2019-10-03 9.0 HIGH 8.8 HIGH
An issue was discovered on PLANEX CS-W50HD devices with firmware before 030720. The device has a command-injection vulnerability in the web management UI on NAS settings page "/cgi-bin/nasset.cgi". An attacker can send a crafted HTTP POST request to execute arbitrary code. Authentication is required before executing the attack.
CVE-2017-12576 1 Planex 2 Cs-qr20, Cs-qr20 Firmware 2019-10-03 9.0 HIGH 7.2 HIGH
An issue was discovered on the PLANEX CS-QR20 1.30. A hidden and undocumented management page allows an attacker to execute arbitrary code on the device when the user is authenticated. The management page was used for debugging purposes, once you login and access the page directly (/admin/system_command.asp), you can execute any command.