VYPR

VDE

by Certvde

CVEs (9)

  • CVE-2026-27546CriSep 16, 2026
    risk 0.64cvss 9.8epss 0.01

    An unauthenticated remote attacker can exploit an authentication bypass in the _account_log function to log in as an admin, even when accounts are properly configured.

  • CVE-2026-14948HigAug 20, 2026
    risk 0.57cvss 8.8epss 0.00

    A low privileged remote attacker can hijack an active administrative session without needing to know the administrator password by extracting live plaintext session identifiers for authenticated users from downloadable error log archives.

  • CVE-2026-8046HigMay 26, 2026
    risk 0.53cvss 8.1epss 0.00

    The affected products insufficiently verify authorization when deleting user accounts. An authenticated, low-privileged remote user can exploit this vulnerability to delete other users, including those with higher privileges.

  • CVE-2026-40813HigMay 27, 2026
    risk 0.49cvss 7.5epss 0.00

    An unauthenticated remote attacker can exploit an unauthenticated SQL Injection vulnerability in the getLiveValues functions tagid parameter due to improper neutralization of special elements in a SQL SELECT command. This can result in a total loss of confidentiality.

  • CVE-2026-14947HigAug 20, 2026
    risk 0.47cvss 7.2epss 0.01

    A high-privileged remote attacker can upload malicious ZIP archive containing directory traversal sequences such as ../ can escape the intended extraction directory and write files to arbitrary locations on the server, potentially achieve arbitrary code execution due to improper…

  • CVE-2026-40852HigMay 27, 2026
    risk 0.47cvss 7.2epss 0.00

    A highly authenticated attacker can alter the config generator injecting a payload into future created configurations. The device is not correctly checking this configuration value before passing it to an system execute leading to code execution. This can result in a total loss…

  • CVE-2026-33617MedApr 2, 2026
    risk 0.34cvss 5.3epss 0.00

    An unauthenticated remote attacker can access a configuration file containing database credentials. This can result in a some loss of confidentiality, but there is no endpoint exposed to use these credentials.

  • CVE-2026-44097HigJul 30, 2026
    risk 0.00cvss 7.1epss 0.00

    A low-privileged remote attacker with "operator" access can upload arbitrary files via the REST endpoint intended for firmware updates, resulting in persistent storage of attacker-controlled files and potentially exhausting resources, which might lead to Denial-of-Service.

  • CVE-2026-14448HigJul 20, 2026
    risk 0.00cvss 7.2epss 0.01

    An high privileged remote attacker can exploit an authenticated OS command injection vulnerability in the system_certificates view due to improper neutralization of special elements in an OS command. This can result in a total loss of confidentiality, availability and integrity.