Known Vulnerabilities for Gryphon Tower by Gryphonconnect
Listed below are 10 of the newest known vulnerabilities associated with "Gryphon Tower" by "Gryphonconnect".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2021-20146 json | An unprotected ssh private key exists on the Gryphon devices which could be used to achieve root access to a server affiliate... | 9.8 - CRITICAL | 2021-12-09 | 2021-12-13 |
| CVE-2021-20145 json | Gryphon Tower routers contain an unprotected openvpn configuration file which can grant attackers access to the Gryphon homeb... | 7.5 - HIGH | 2021-12-09 | 2021-12-13 |
| CVE-2021-20144 json | An unauthenticated command injection vulnerability exists in the parameters of operation 49 in the controller_server service ... | 8.8 - HIGH | 2021-12-09 | 2021-12-13 |
| CVE-2021-20143 json | An unauthenticated command injection vulnerability exists in the parameters of operation 48 in the controller_server service ... | 8.8 - HIGH | 2021-12-09 | 2021-12-13 |
| CVE-2021-20142 json | An unauthenticated command injection vulnerability exists in the parameters of operation 41 in the controller_server service ... | 8.8 - HIGH | 2021-12-09 | 2021-12-13 |
| CVE-2021-20141 json | An unauthenticated command injection vulnerability exists in the parameters of operation 32 in the controller_server service ... | 8.8 - HIGH | 2021-12-09 | 2021-12-13 |
| CVE-2021-20140 json | An unauthenticated command injection vulnerability exists in the parameters of operation 10 in the controller_server service ... | 8.8 - HIGH | 2021-12-09 | 2021-12-13 |
| CVE-2021-20139 json | An unauthenticated command injection vulnerability exists in the parameters of operation 3 in the controller_server service o... | 8.8 - HIGH | 2021-12-09 | 2021-12-13 |
| CVE-2021-20138 json | An unauthenticated command injection vulnerability exists in multiple parameters in the Gryphon Tower router’s web interfac... | 8.8 - HIGH | 2021-12-09 | 2021-12-13 |
| CVE-2021-20137 json | A reflected cross-site scripting vulnerability exists in the url parameter of the /cgi-bin/luci/site_access/ page on the Gryp... | 6.1 - MEDIUM | 2021-12-09 | 2021-12-13 |