VYPR

VDE-2026-055

by Certvde

CVEs (5)

  • CVE-2026-44469HigMay 26, 2026
    risk 0.51cvss 7.8epss 0.00

    The affected product extracts installation files to a temporary directory with incorrect default permissions during administrative installation. A low-privileged local attacker can exploit a TOCTOU race condition with a practical time window to replace verified files with…

  • CVE-2026-44468HigMay 26, 2026
    risk 0.51cvss 7.8epss 0.00

    The affected product creates a directory with insecure default permissions during administrative installation. This allows a low-privileged local attacker to modify a temporary file defining the components to be installed, enabling local privilege escalation by forcing the…

  • CVE-2026-8047HigMay 26, 2026
    risk 0.49cvss 7.5epss 0.00

    The affected products perform improper length checking when parsing incoming HTTP requests, resulting in a size-limited out-of-bounds write. An unauthenticated remote attacker can exploit this flaw to cause a denial of service via a system crash on the affected device.

  • CVE-2026-10521HigJun 23, 2026
    risk 0.47cvss 7.2epss 0.00

    An high privileged remote attacker can access a hidden configuration method, that should not be accessible by any user, to modify critical program parameters. This can result in a total loss of confidentiality, integrity and availability.

  • CVE-2026-7849CriJul 30, 2026
    risk 0.00cvss 9.8epss 0.00

    Due to improper neutralization of special elements, an unauthenticated remote attacker is able to inject a command into the system configuration which is subsequently executed as root.