VYPR

ICS Advisories

by Cisagov

CVEs (29)

  • CVE-2025-31147MedApr 15, 2025
    risk 0.34cvss 5.3epss 0.00

    Unauthenticated attackers can query information about total energy consumed by EV chargers of arbitrary users.

  • CVE-2025-25276MedApr 15, 2025
    risk 0.34cvss 5.3epss 0.00

    An unauthenticated attacker can hijack other users' devices and potentially control them.

  • CVE-2025-24315MedApr 15, 2025
    risk 0.34cvss 5.3epss 0.01

    Unauthenticated attackers can add devices of other users to their scenes (or arbitrary scenes of other arbitrary users).

  • CVE-2025-31357MedApr 15, 2025
    risk 0.34cvss 5.3epss 0.00

    An unauthenticated attacker can obtain a user's plant list by knowing the username.

  • CVE-2025-30514MedApr 15, 2025
    risk 0.34cvss 5.3epss 0.00

    Unauthenticated attackers can obtain restricted information about a user's smart device collections (i.e., "scenes").

  • CVE-2025-27938MedApr 15, 2025
    risk 0.34cvss 5.3epss 0.00

    Unauthenticated attackers can obtain restricted information about a user's smart device collections (i.e., "rooms").

  • CVE-2022-2137MedJul 22, 2022
    risk 0.32cvss 4.9epss 0.01

    The affected product is vulnerable to two SQL injections that require high privileges for exploitation and may allow an unauthorized attacker to disclose information

  • CVE-2024-38279MedJun 13, 2024
    risk 0.30cvss 4.6epss 0.00

    The affected product is vulnerable to an attacker modifying the bootloader by using custom arguments to bypass authentication and gain access to the file system and obtain password hashes.

  • CVE-2024-39278MedSep 5, 2024
    risk 0.27cvss 4.2epss 0.00

    Credentials to access device configuration information stored unencrypted in flash memory. These credentials would allow read-only access to network configuration information and terminal configuration data.

Page 2 of 2