Search: "mimosa"

9 CVEs found

An issue was discovered on Mimosa Client Radios before 2.2.3 and Mimosa Backhaul Radios before 2.2.3. By connecting to the Mosquitto broker on an access point and one of its clients, an attacker can g...

Published: 2017-05-21
Products: 2
Vendors:
mimosa

A hard-coded credentials issue was discovered on Mimosa Client Radios before 2.2.3, Mimosa Backhaul Radios before 2.2.3, and Mimosa Access Points before 2.2.3. These devices run Mosquitto, a lightweig...

Published: 2017-05-21
Products: 2
Vendors:
mimosa

An issue was discovered on Mimosa Client Radios before 2.2.3 and Mimosa Backhaul Radios before 2.2.3. In the device's web interface, after logging in, there is a page that allows you to ping other hos...

Published: 2017-05-21
Products: 2
Vendors:
mimosa

An information-leakage issue was discovered on Mimosa Client Radios before 2.2.3 and Mimosa Backhaul Radios before 2.2.3. There is a page in the web interface that will show you the device's serial nu...

Published: 2017-05-21
Products: 2
Vendors:
mimosa

An issue was discovered on Mimosa Client Radios before 2.2.4 and Mimosa Backhaul Radios before 2.2.4. On the backend of the device's web interface, there are some diagnostic tests available that are n...

Published: 2017-05-21
Products: 2
Vendors:
mimosa

An issue was discovered on Mimosa Client Radios before 2.2.3. In the device's web interface, there is a page that allows an attacker to use an unsanitized GET parameter to download files from the devi...

Published: 2017-05-21
Products: 2
Vendors:
mimosa
CVE-2020-25205
6.1 MEDIUM

The web console for Mimosa B5, B5c, and C5x firmware through 2.8.0.2 is vulnerable to stored XSS in the set_banner() function of /var/www/core/controller/index.php. An unauthenticated attacker may set...

Published: 2021-07-20
Products: 6
Vendors:
mimosa

The web console for Mimosa B5, B5c, and C5x firmware through 2.8.0.2 allows authenticated command injection in the Throughput, WANStats, PhyStats, and QosStats API classes. An attacker with access to ...

Published: 2021-07-20
Products: 6
Vendors:
mimosa
CVE-2022-21215
10.0 CRITICAL

This vulnerability could allow an attacker to force the server to create and execute a web request granting access to backend APIs that are only accessible to the Mimosa MMP server, or request pages t...

Published: 2022-02-18
Products: 9
Vendors:
airspan