High severity7.5NVD Advisory· Published Mar 4, 2022· Updated Jun 17, 2026
CVE-2021-40846
CVE-2021-40846
Description
An issue was discovered in Rhinode Trading Paints through 2.0.36. TP Updater.exe uses cleartext HTTP to check, and request, updates. Thus, attackers can man-in-the-middle a victim to download a malicious binary in place of the real update, with no SSL errors or warnings.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- Rhinode Trading Paints/Rhinode Trading Paintsdescription
- Range: <=2.0.36
Patches
Vulnerability mechanics
References
2- axelp.io/YWDACnvdExploitThird Party Advisory
- www.tradingpaints.com/page/PrivacynvdVendor Advisory
News mentions
0No linked articles in our index yet.