Corega
12 CVEs tracked since 2015. Since Dec 2015, none of them reached CISA KEV.
Corega CVEs per month
| Month | CVEs | In CISA KEV |
|---|---|---|
| 2015-12 | 3 | 0 |
| 2016-01 | null or fewer | |
| 2016-02 | null or fewer | |
| 2016-03 | 1 | 0 |
| 2016-04 | null or fewer | |
| 2016-05 | null or fewer | |
| 2016-06 | 3 | 0 |
| 2016-07 | null or fewer | |
| 2016-08 | null or fewer | |
| 2016-09 | null or fewer | |
| 2016-10 | null or fewer | |
| 2016-11 | null or fewer | |
| 2016-12 | null or fewer | |
| 2017-01 | null or fewer | |
| 2017-02 | null or fewer | |
| 2017-03 | null or fewer | |
| 2017-04 | null or fewer | |
| 2017-05 | null or fewer | |
| 2017-06 | null or fewer | |
| 2017-07 | null or fewer | |
| 2017-08 | null or fewer | |
| 2017-09 | 2 | 0 |
| 2017-10 | null or fewer | |
| 2017-11 | null or fewer | |
| 2017-12 | null or fewer | |
| 2018-01 | null or fewer | |
| 2018-02 | null or fewer | |
| 2018-03 | 3 | 0 |
Products
The products that kept showing up in Corega's monthly top three, with their CVEs summed over those months.
Latest CVEs
The 15 most recently published vulnerabilities affecting Corega.
- CVE-2017-10853Buffer overflow in Corega CG-WGR1200 firmware 2.20 and earlier allows an attacker to execute arbitrary commands via unspecified vectors.8.8
- CVE-2017-10852Buffer overflow in Corega CG-WGR1200 firmware 2.20 and earlier allows an attacker to execute arbitrary code via unspecified vectors.8.8
- CVE-2017-10854Corega CG-WGR1200 firmware 2.20 and earlier allows an attacker to bypass authentication and change the login password via unspecified vectors.8.8
- CVE-2017-10813CG-WLR300NM Firmware version 1.90 and earlier allows an attacker to execute arbitrary OS commands via unspecified vectors.6.8
- CVE-2017-10814Buffer overflow in CG-WLR300NM Firmware version 1.90 and earlier allows an attacker to execute arbitrary code via unspecified vectors.6.8
- CVE-2016-7810Cross-site scripting vulnerability in Corega CG-WLR300NX firmware Ver. 1.20 and earlier allows attacker with administrator rights to inject arbitrary web script or HTML via unspecified vectors.4.8
- CVE-2016-7809Cross-site request forgery (CSRF) vulnerability in Corega CG-WLR300NX firmware Ver. 1.20 and earlier allows remote attackers to hijack the authentication of logged in user to conduct unintended ope...8.8
- CVE-2016-7811Corega CG-WLR300NX firmware Ver. 1.20 and earlier allows an attacker on the same network segment to bypass access restriction to perform arbitrary operations via unspecified vectors.8.8
- CVE-2016-7808Cross-site scripting vulnerability in Corega CG-WLBARGMH and CG-WLBARGNL allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.6.1
- CVE-2016-4822Corega CG-WLBARGL devices allow remote authenticated users to execute arbitrary commands via unspecified vectors.8.0
- CVE-2016-4824The Wi-Fi Protected Setup (WPS) implementation on Corega CG-WLR300GNV and CG-WLR300GNV-W devices does not restrict the number of PIN authentication attempts, which makes it easier for remote attack...5.3
- CVE-2016-4823Corega CG-WLBARAGM devices allow remote attackers to cause a denial of service (reboot) via unspecified vectors.7.5
- CVE-2016-1158Cross-site request forgery (CSRF) vulnerability on Corega CG-WLBARGMH and CG-WLBARGNL devices allows remote attackers to hijack the authentication of administrators for requests that perform admini...8.8
- CVE-2015-7792Corega CG-WLBARGS devices allow remote attackers to perform administrative operations via unspecified vectors.9.8
- CVE-2015-7794Corega CG-WLNCM4G devices provide an open DNS resolver, which allows remote attackers to cause a denial of service (traffic amplification) via crafted queries.5.8
The record
- Peak rank
- #40 in Dec 2015
- Busiest month shown
- Dec 2015, 3 CVEs
- Months with a KEV entry
- 0 since Dec 2015
- Monthly snapshots
- 5 since 2015