VYPR

Homelynk Firmware

by Schneider Electric

CVEs (10)

  • CVE-2021-22738CriMay 26, 2021
    risk 0.64cvss 9.8epss 0.01

    Use of a Broken or Risky Cryptographic Algorithm vulnerability exists in homeLYnk (Wiser For KNX) and spaceLYnk V2.60 and prior that could cause unauthorized access when credentials are discovered after a brute force attack.

  • CVE-2021-22737CriMay 26, 2021
    risk 0.64cvss 9.8epss 0.01

    Insufficiently Protected Credentials vulnerability exists in homeLYnk (Wiser For KNX) and spaceLYnk V2.60 and prior that could cause unauthorized access of when credentials are discovered after a brute force attack.

  • CVE-2021-22733HigMay 26, 2021
    risk 0.51cvss 7.8epss 0.00

    Improper Privilege Management vulnerability exists in homeLYnk (Wiser For KNX) and spaceLYnk V2.60 and prior which could cause shell access when unauthorized code is loaded into the system folder.

  • CVE-2021-22732HigMay 26, 2021
    risk 0.51cvss 7.8epss 0.00

    Improper Privilege Management vulnerability exists in homeLYnk (Wiser For KNX) and spaceLYnk V2.60 and prior which could cause a code execution issue when an attacker loads unauthorized code on the web server.

  • CVE-2021-22736HigMay 26, 2021
    risk 0.49cvss 7.5epss 0.01

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists in homeLYnk (Wiser For KNX) and spaceLYnk V2.60 and prior which could cause a denial of service when an unauthorized file is uploaded.

  • CVE-2018-7779HigJul 3, 2018
    risk 0.49cvss 7.5epss 0.01

    In Schneider Electric Wiser for KNX V2.1.0 and prior, homeLYnk V2.0.1 and prior; and spaceLYnk V2.1.0 and prior, weak and unprotected FTP access could allow an attacker unauthorized access.

  • CVE-2021-22735HigMay 26, 2021
    risk 0.47cvss 7.2epss 0.01

    Improper Verification of Cryptographic Signature vulnerability exists inhomeLYnk (Wiser For KNX) and spaceLYnk V2.60 and prior which could allow remote code execution when unauthorized code is copied to the device.

  • CVE-2021-22734HigMay 26, 2021
    risk 0.47cvss 7.2epss 0.01

    Improper Verification of Cryptographic Signature vulnerability exists in homeLYnk (Wiser For KNX) and spaceLYnk V2.60 and prior which could cause remote code execution when an attacker loads unauthorized code.

  • CVE-2021-22740MedMay 26, 2021
    risk 0.42cvss 6.5epss 0.01

    Information Exposure vulnerability exists in homeLYnk (Wiser For KNX) and spaceLYnk V2.60 and prior which could cause information to be exposed when an unauthorized file is uploaded.

  • CVE-2021-22739MedMay 26, 2021
    risk 0.38cvss 5.9epss 0.01

    Information Exposure vulnerability exists in homeLYnk (Wiser For KNX) and spaceLYnk V2.60 and prior which could cause a device to be compromised when it is first configured.