corega 関連製品全体の CVE とセキュリティ脆弱性情報を集約し、CVSS、EPSS、公開日、脆弱性情報データを掲載しています。
一般的な弱点パターンには バッファオーバーフロー、vendor risk cross-site scripting、vendor risk csrf, and vendor risk input validation があり、vendor surface software deployment の利用場面で アプリケーションクラッシュ、vendor impact memory corruption, and vendor impact session compromise などのリスクが生じる可能性があります。
掲載データは公開脆弱性情報とセキュリティ公告に基づき、過去の暴露面と修補優先度の評価に利用できます。
| CVE | 概要 | ソース | CVSS 最大値 | EPSS(%) | 公開 | 更新 |
|---|---|---|---|---|---|---|
| CVE-2017-10854 | Corega CG-WGR1200 firmware 2.20 and earlier allows an attacker to bypass authentication and change the login password via unspecified vectors. | [email protected] | 8.8 | 0.62% | 2018-03-09 | 2026-06-16 |
| CVE-2017-10853 | Buffer overflow in Corega CG-WGR1200 firmware 2.20 and earlier allows an attacker to execute arbitrary commands via unspecified vectors. | [email protected] | 8.8 | 0.82% | 2018-03-09 | 2026-06-16 |
| CVE-2017-10852 | Buffer overflow in Corega CG-WGR1200 firmware 2.20 and earlier allows an attacker to execute arbitrary code via unspecified vectors. | [email protected] | 8.8 | 0.87% | 2018-03-09 | 2026-06-16 |
| CVE-2017-10814 | Buffer overflow in CG-WLR300NM Firmware version 1.90 and earlier allows an attacker to execute arbitrary code via unspecified vectors. | [email protected] | 6.8 | 0.82% | 2017-09-15 | 2026-06-16 |
| CVE-2017-10813 | CG-WLR300NM Firmware version 1.90 and earlier allows an attacker to execute arbitrary OS commands via unspecified vectors. | [email protected] | 6.8 | 0.66% | 2017-09-15 | 2026-06-16 |
| CVE-2016-7811 | Corega CG-WLR300NX firmware Ver. 1.20 and earlier allows an attacker on the same network segment to bypass access restriction to perform arbitrary operations via unspecified vectors. | [email protected] | 8.8 | 0.89% | 2017-06-09 | 2026-06-16 |
| CVE-2016-7810 | Cross-site scripting vulnerability in Corega CG-WLR300NX firmware Ver. 1.20 and earlier allows attacker with administrator rights to inject arbitrary web script or HTML via unspecified vectors. | [email protected] | 4.8 | 0.77% | 2017-06-09 | 2026-06-16 |
| CVE-2016-7809 | Cross-site request forgery (CSRF) vulnerability in Corega CG-WLR300NX firmware Ver. 1.20 and earlier allows remote attackers to hijack the authentication of logged in user to conduct unintended operations via unspecified vectors. | [email protected] | 8.8 | 0.91% | 2017-06-09 | 2026-06-16 |
| CVE-2016-7808 | Cross-site scripting vulnerability in Corega CG-WLBARGMH and CG-WLBARGNL allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | [email protected] | 6.1 | 1.20% | 2017-06-09 | 2026-06-16 |
| CVE-2016-4824 | The Wi-Fi Protected Setup (WPS) implementation on Corega CG-WLR300GNV and CG-WLR300GNV-W devices does not restrict the number of PIN authentication attempts, which makes it easier for remote attackers to obtain network access via a brute-force attack. | [email protected] | 5.3 | 1.39% | 2016-06-25 | 2026-06-16 |
| CVE-2016-4823 | Corega CG-WLBARAGM devices allow remote attackers to cause a denial of service (reboot) via unspecified vectors. | [email protected] | 7.5 | 1.94% | 2016-06-25 | 2026-06-16 |
| CVE-2016-4822 | Corega CG-WLBARGL devices allow remote authenticated users to execute arbitrary commands via unspecified vectors. | [email protected] | 8.0 | 1.07% | 2016-06-25 | 2026-06-16 |
| CVE-2016-1158 | Cross-site request forgery (CSRF) vulnerability on Corega CG-WLBARGMH and CG-WLBARGNL devices allows remote attackers to hijack the authentication of administrators for requests that perform administrative functions. | [email protected] | 8.8 | 0.62% | 2016-03-03 | 2026-06-16 |
| CVE-2015-7794 | Corega CG-WLNCM4G devices provide an open DNS resolver, which allows remote attackers to cause a denial of service (traffic amplification) via crafted queries. | [email protected] | 5.8 | 1.60% | 2015-12-30 | 2026-06-16 |
| CVE-2015-7793 | Corega CG-WLBARAGM devices provide an open proxy service, which allows remote attackers to trigger outbound network traffic via unspecified vectors. | [email protected] | 5.8 | 1.60% | 2015-12-30 | 2026-06-16 |
| CVE-2015-7792 | Corega CG-WLBARGS devices allow remote attackers to perform administrative operations via unspecified vectors. | [email protected] | 9.8 | 2.76% | 2015-12-30 | 2026-06-16 |