CVE Tools

Hot

6 CVEs tracked since 2013. Since Dec 2013, none of them reached CISA KEV.

Hot CVEs per month

Dec 2013 to Dec 2013. Point at a month, or focus the strip and use the arrow keys.
Hot CVEs per month, with the share now in CISA KEV
MonthCVEsIn CISA KEV
2013-1260

Products

The products that kept showing up in Hot's monthly top three, with their CVEs summed over those months.

  1. Hotbox Router61 month
  2. Hotbox Router Firmware61 month

Latest CVEs

The 6 most recently published vulnerabilities affecting Hot.

  1. CVE-2013-5218Cross-site scripting (XSS) vulnerability on the HOT HOTBOX router with software 2.1.11 allows remote attackers to inject arbitrary web script or HTML via a crafted DHCP Host Name option, which is n...2.9
  2. CVE-2013-5038The HOT HOTBOX router with software 2.1.11 allows remote attackers to bypass authentication by configuring a source IP address that had previously been used for an authenticated session.5.8
  3. CVE-2013-5219Directory traversal vulnerability on the HOT HOTBOX router with software 2.1.11 allows remote attackers to read arbitrary files via a .. (dot dot) in a URI, as demonstrated by a request for /etc/pa...3.3
  4. CVE-2013-5220goform/login on the HOT HOTBOX router with software 2.1.11 allows remote attackers to cause a denial of service (device crash) via crafted HTTP POST data.6.1
  5. CVE-2013-5039Cross-site request forgery (CSRF) vulnerability in goform/wlanBasicSecurity on the HOT HOTBOX router with software 2.1.11 allows remote attackers to hijack the authentication of administrators for ...5.4
  6. CVE-2013-5037The HOT HOTBOX router with software 2.1.11 has a default WPS PIN of 12345670, which makes it easier for remote attackers to obtain the WPA or WPA2 pre-shared key via EAP messages.3.3

The record

Peak rank
#25 in Dec 2013
Busiest month shown
Dec 2013, 6 CVEs
Months with a KEV entry
0 since Dec 2013
Monthly snapshots
1 since 2013
Hot's full record, month by month

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store