📦

smart_box

Vendor: beeline

Actively Exploited 0 CISA KEV List
PoC / Exploits 0 Code Available
Total RCEs 1 Remote Access
Total CVEs 4 Total Indexed
Avg. EPSS 2.21% Exploit Prob.
Latest CVE CVE-2021-41427 Nov 10

Security Vulnerability Index

Page 1 / 1
6.1 CVSS

Beeline Smart Box 2.0.38 is vulnerable to Cross Site Scripting (XSS) via the choose_mac parameter to setup.cgi.

EPSS: 1.04%
8.8 CVSS

Beeline Smart box 2.0.38 is vulnerable to Cross Site Request Forgery (CSRF) via mgt_end_user.htm.

EPSS: 0.69%
8.8 CVSS

Beeline Smart Box 2.0.38 routers allow "Advanced settings > Other > Diagnostics" OS command injection via the Ping ping_ipaddr parameter, the Nslookup nslookup_ipaddr parameter, or the Traceroute traceroute_ipaddr parameter.

EPSS: 4.90%