Products: 2
    Vulnerabilities: 12
    Known Exploited: 0
    3
    Critical Level Threats
    5
    High Level Threats
    4
    Medium Level Threats
    0
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2025-56498

    An OS command injection vulnerability exists in PLDT WiFi Router's Prolink PGN6401V Firmware 8.1.2 web management interface. The ping6.asp page submits user input to the /boaform/formPing6 endpoint via the pingAddr parameter, which is not properly sanitized. An authenticated attacker can exploit this flaw by injecting arbitrary system commands, which are executed by the underlying operating system with root privileges. The router uses the Boa web server (version 0.93.15) to handle the request. Successful exploitation can lead to full system compromise and unauthorized control of the network device.

    Last Modified: Sep 09, 2025
    Published: Sep 03, 2025

    CVE-2024-43367

    Boa has an uncaught exception when transitioning the state of `AsyncGenerator` objects

    Last Modified: Apr 15, 2026
    Published: Aug 15, 2024

    CVE-2022-45956

    Boa Web Server versions 0.94.13 through 0.94.14 fail to validate the correct security constraint on the HEAD HTTP method allowing everyone to bypass the Basic Authorization mechanism.

    Last Modified: Apr 22, 2025
    Published: Dec 12, 2022

    CVE-2022-44117

    Boa 0.94.14rc21 is vulnerable to SQL Injection via username. NOTE: the is disputed by multiple third parties because Boa does not ship with any support for SQL.

    Last Modified: Nov 21, 2024
    Published: Nov 23, 2022

    CVE-2021-33558

    Boa 0.94.13 allows remote attackers to obtain sensitive information via a misconfiguration involving backup.html, preview.html, js/log.js, log.html, email.html, online-users.html, and config.js. NOTE: multiple third parties report that this is a site-specific issue because those files are not part of Boa.

    Last Modified: Nov 21, 2024
    Published: May 27, 2021
    Items Per Page
    Boa Vulnerabilities & Security CVEs | CVE-DB