VendorsMeinbwadirex-proall versions
Vulnerabilities

Meinbwa BWA Technology DiREX-Pro

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

3CVEs
CVE-2020-10250
BWA DiREX-Pro 1.2181 devices allow remote attackers to execute arbitrary OS commands via shell metacharacters in the PKG parameter to uninstall.php3.
Published 2020-03-09 · Modified
10.0EPSS 0.026
CVE-2020-10248
BWA DiREX-Pro 1.2181 devices allow remote attackers to discover passwords via a direct request to val_users.php3.
Published 2020-03-09 · Modified
7.5EPSS 0.014
CVE-2020-10249
BWA DiREX-Pro 1.2181 devices allow full path disclosure via an invalid name array parameter to val_soft.php3.
Published 2020-03-09 · Modified
5.3EPSS 0.010