Products: 1
    Vulnerabilities: 26
    Known Exploited: 0
    2
    Critical Level Threats
    7
    High Level Threats
    17
    Medium Level Threats
    0
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2022-40895

    In certain Nedi products, a vulnerability in the web UI of NeDi login & Community login could allow an unauthenticated, remote attacker to affect the integrity of a device via a User Enumeration vulnerability. The vulnerability is due to insecure design, where a difference in forgot password utility could allow an attacker to determine if the user is valid or not, enabling a brute force attack with valid users. This affects NeDi 1.0.7 for OS X 1.0.7 <= and NeDi for Suse 1.0.7 <= and NeDi for FreeBSD 1.0.7 <=.

    Last Modified: Nov 21, 2024
    Published: Oct 06, 2022

    CVE-2021-26751

    NeDi 1.9C allows an authenticated user to perform a SQL Injection in the Monitoring History function on the endpoint /Monitoring-History.php via the det HTTP GET parameter. This allows an attacker to access all the data in the database and obtain access to the NeDi application.

    Last Modified: Nov 21, 2024
    Published: Feb 12, 2021

    CVE-2021-26752

    NeDi 1.9C allows an authenticated user to execute operating system commands in the Nodes Traffic function on the endpoint /Nodes-Traffic.php via the md or ag HTTP GET parameter. This allows an attacker to obtain access to the operating system where NeDi is installed and to all application data.

    Last Modified: Nov 21, 2024
    Published: Feb 12, 2021

    CVE-2021-26753

    NeDi 1.9C allows an authenticated user to inject PHP code in the System Files function on the endpoint /System-Files.php via the txt HTTP POST parameter. This allows an attacker to obtain access to the operating system where NeDi is installed and to all application data.

    Last Modified: Nov 21, 2024
    Published: Feb 12, 2021

    CVE-2020-23868

    NeDi 1.9C allows inc/rt-popup.php d XSS.

    Last Modified: Nov 21, 2024
    Published: Nov 02, 2020
    Items Per Page
    Nedi Vulnerabilities & Security CVEs | CVE-DB