Vulnerabilities (CVE)

Filtered by vendor Allnet Subscribe
Total 3 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2025-29269 1 Allnet 2 All-rut22gw, All-rut22gw Firmware 2025-12-16 N/A 9.8 CRITICAL
ALLNET ALL-RUT22GW v3.3.8 was discovered to contain an OS command injection vulnerability via the command parameter in the popen.cgi endpoint.
CVE-2025-29268 1 Allnet 2 All-rut22gw, All-rut22gw Firmware 2025-12-16 N/A 9.8 CRITICAL
ALLNET ALL-RUT22GW v3.3.8 was discovered to store hardcoded credentials in the libicos.so library.
CVE-2022-34767 1 Allnet 2 All-wr0500ac, All-wr0500ac Firmware 2024-11-21 N/A 5.9 MEDIUM
Web page which "wizardpwd.asp" ALLNET Router model WR0500AC is prone to Authorization bypass vulnerability – the password, located at "admin" allows changing the http[s]://wizardpwd.asp/cgi-bin. Does not validate the user's identity and can be accessed publicly.