Início
Tendências
Vulnerabilidades
Notícias
Pesquisadores
Por que dbugs?

Karn Ganeshan

#16820de 53,638
16CVSS total
Vulnerabilidades · 2
Média
1
Alta
1
PT-2017-8773
6.0
2017-10-13
Jantek · Jantek Jtc-200 · CVE-2016-5789
**Name of the Vulnerable Software and Affected Versions** JanTek JTC-200 (all versions) **Description** A Cross-site Request Forgery issue allows an attacker to perform actions with the same permissions as a victim user, provided the victim has an active session and is induced to trigger the malicious request. **Recommendations** For all versions, consider implementing measures to prevent Cross-site Request Forgery attacks, such as validating request origins and using anti-CSRF tokens, until a patch is available.
PT-2017-3117
10
2017-10-12
Jantek · Jantek Jtc-200 · CVE-2016-5791
**Name of the Vulnerable Software and Affected Versions** JanTek JTC-200, all versions **Description** An issue with improper authentication was found, allowing access to an undocumented BusyBox Linux shell over the TELNET service without authentication. This could enable a remote attacker to bypass authentication procedures and gain access to the shell. **Recommendations** For all versions, consider disabling the TELNET service as a temporary workaround until a patch is available. Restrict access to the BusyBox Linux shell to minimize the risk of exploitation.