Filtered by vendor Belkin Subscriptions
Filtered by product N300 Subscriptions
Total 5 CVE
CVE Vendors Products Updated CVSS v3.1
CVE-2022-30105 1 Belkin 2 N300, N300 Firmware 2022-05-30 9.8 Critical
In Belkin N300 Firmware 1.00.08, the script located at /setting_hidden.asp, which is accessible before and after configuring the device, exhibits multiple remote command injection vulnerabilities. The following parameters in the [form name] form; [list vulnerable parameters], are not properly sanitized after being submitted to the web interface in a POST request. With specially crafted parameters, it is possible to inject a an OS command which will be executed with root privileges, as the web interface, and all processes on the device, run as root.
CVE-2013-3091 1 Belkin 2 N300, N300 Firmware 2020-02-10 9.8 Critical
An Authentication Bypass vulnerability in Belkin N300 (F7D7301v1) router allows remote attackers to bypass authentication using "Javascript debugging."
CVE-2013-3090 1 Belkin 1 N300 2017-08-29 N/A
Multiple cross-site scripting (XSS) vulnerabilities in Belkin N300 router allow remote attackers to inject arbitrary web script or HTML via the Guest Access PSK field to wireless_guest2_print.stm or other unspecified vectors.
CVE-2013-3092 1 Belkin 2 N300, N300 Firmware 2014-10-01 N/A
The Belkin N300 (F7D7301v1) router allows remote attackers to bypass authentication and gain privileges via vectors related to incorrect validation of the HTTP Authorization header.
CVE-2013-3089 1 Belkin 2 N300, N300 Firmware 2014-10-01 N/A
Cross-site request forgery (CSRF) vulnerability in apply.cgi in Belkin N300 (F7D7301v1) router allows remote attackers to hijack the authentication of administrators for requests that modify configuration.