VendorsKorenixjetwave_2212xall versions
Vulnerabilities

Korenix JetWave 2212X

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

7CVEs
CVE-2020-12501
Pepperl+Fuchs improper authorization affects multiple Comtrol RocketLinx products
Published 2020-10-15 · Modified
9.8EPSS 0.033
CVE-2020-12504
Pepperl+Fuchs improper authorization affects multiple Comtrol RocketLinx products
Published 2020-10-15 · Modified
9.8EPSS 0.030
CVE-2021-39280
Certain Korenix JetWave devices allow authenticated users to execute arbitrary code as root via /syscmd.asp. This affects 2212X before 1.9.1, 2212S before 1.9.1, 2212G before 1.8, 3220 V3 before 1.5.1, 3420 V3 before 1.5.1, and 2311 through 2022-01-31.
Published 2022-02-06 · Modified
9.0EPSS 0.023
CVE-2023-23295
Korenix Jetwave 4200 Series 1.3.0 and JetWave 3000 Series 1.6.0 are vulnerable to Command Injection via /goform/formSysCmd. An attacker an modify the sysCmd parameter in order to execute commands as root.
Published 2023-02-23 · Modified
8.8EPSS 0.038
CVE-2023-23294
Korenix JetWave 4200 Series 1.3.0 and JetWave 3000 Series 1.6.0 are vulnerable to Command Injection. An attacker can modify the file_name parameter to execute commands as root.
Published 2023-02-23 · Modified
8.8EPSS 0.027
CVE-2020-12503
Pepperl+Fuchs improper authorization affects multiple Comtrol RocketLinx products
Published 2020-10-15 · Modified
7.2EPSS 0.233
CVE-2023-23296
Korenix JetWave 4200 Series 1.3.0 and JetWave 3200 Series 1.6.0 are vulnerable to Denial of Service via /goform/formDefault.
Published 2023-02-23 · Modified
6.5EPSS 0.008