VendorsCONNECTIZEac21000_g6_firmware641.139.1.1256
Vulnerabilities

CONNECTIZE AC21000 G6 Firmware 641.139.1.1256

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

7CVEs
CVE-2023-24049
An issue was discovered on Connectize AC21000 G6 641.139.1.1256 allows attackers to gain escalated privileges on the device via poor credential management.
Published 2023-12-04 · Modified
9.8EPSS 0.007
CVE-2023-24051
A client side rate limit issue discovered in Connectize AC21000 G6 641.139.1.1256 allows attackers to gain escalated privileges via brute force style attacks.
Published 2023-12-04 · Modified
9.8EPSS 0.007
CVE-2023-24052
An issue discovered in Connectize AC21000 G6 641.139.1.1256 allows attackers to gain control of the device via the change password functionality as it does not prompt for the current password.
Published 2023-12-04 · Modified
9.8EPSS 0.007
CVE-2023-24046
An issue was discovered on Connectize AC21000 G6 641.139.1.1256 allows attackers to run arbitrary commands via use of a crafted string in the ping utility.
Published 2023-12-04 · Modified
8.8EPSS 0.006
CVE-2023-24048
Cross Site Request Forgery (CSRF) vulnerability in Connectize AC21000 G6 641.139.1.1256 allows attackers to gain control of the device via crafted GET request to /man_password.htm.
Published 2023-12-04 · Modified
8.8EPSS 0.003
CVE-2023-24047
An Insecure Credential Management issue discovered in Connectize AC21000 G6 641.139.1.1256 allows attackers to gain escalated privileges via use of weak hashing algorithm.
Published 2023-12-04 · Modified
8.0EPSS 0.004
CVE-2023-24050
Cross Site Scripting (XSS) vulnerability in Connectize AC21000 G6 641.139.1.1256 allows attackers to run arbitrary code via crafted string when setting the Wi-Fi password in the admin panel.
Published 2023-12-04 · Modified
5.4EPSS 0.004