VYPR

certvde

by Certvde

CVEs (13)

  • CVE-2026-27565CriSep 16, 2026
    risk 0.64cvss 9.8epss 0.01

    An unauthenticated remote attacker can upload a malicious IODD file that places and executes a shell script with root privileges. The shell script remains active even after a reboot.

  • CVE-2026-33615CriApr 2, 2026
    risk 0.59cvss 9.1epss 0.01

    An unauthenticated remote attacker can exploit an unauthenticated SQL Injection vulnerability in the setinfo endpoint due to improper neutralization of special elements in a SQL UPDATE command. This can result in a total loss of integrity and availability.

  • CVE-2026-27559HigSep 16, 2026
    risk 0.57cvss 8.8epss 0.03

    A low-privileged remote attacker can exploit a command injection vulnerability in the /api/status/data endpoint by sending a crafted GET request with user credentials allowing execution of commands with root privileges on the device.

  • CVE-2026-27558HigSep 16, 2026
    risk 0.57cvss 8.8epss 0.03

    A low-privileged remote attacker can exploit a command injection vulnerability in the /index.php/attached_devices_tab/ajax_remove_uploaded_iodd_files endpoint using operator credentials allowing execution of commands with root privileges on the device.

  • CVE-2026-27556HigSep 16, 2026
    risk 0.57cvss 8.8epss 0.01

    A low-privileged remote attacker can exploit a local file inclusion vulnerability in the /index.php/ajax/save_iodd_parameters endpoint using a valid operator cookie allowing execution of arbitrary PHP code on the device.

  • CVE-2026-27555HigSep 16, 2026
    risk 0.57cvss 8.8epss 0.01

    A low-privileged remote attacker can exploit a local file inclusion vulnerability in the /index.php/ajax/get_iodd_port_info endpoint using a valid user cookie allowing execution of arbitrary PHP code on the device.

  • CVE-2026-27554HigSep 16, 2026
    risk 0.57cvss 8.8epss 0.03

    A low-privileged remote attacker can exploit a command injection vulnerability in the /index.php/ajax/save_iodd_parameters endpoint using operator credentials allowing execution of commands with root privileges on the device.

  • CVE-2026-27548HigSep 16, 2026
    risk 0.57cvss 8.8epss 0.03

    A low-privileged remote attacker can exploit a command injection vulnerability in the /index.php/ajax/get_iodd_port_info endpoint using user or operator credentials allowing execution of commands with root privileges on the device.

  • CVE-2026-27547HigSep 16, 2026
    risk 0.57cvss 8.8epss 0.03

    A low-privileged remote attacker can exploit a command injection vulnerability in the /index.php/ajax/get_iodd_menu_info endpoint using valid user or operator credentials allowing execution of commands with root privileges on the device.

  • CVE-2026-27557HigSep 16, 2026
    risk 0.49cvss 7.5epss 0.01

    An unauthenticated remote attacker can exploit a path traversal vulnerability in the /index.php/view_uploaded_iodd_file endpoint allowing the SSH server's private keys to be read.

  • CVE-2026-27563HigSep 16, 2026
    risk 0.47cvss 7.2epss 0.03

    A high-privileged remote attacker can exploit a command injection vulnerability in the /api/datastorage/data endpoint by sending a crafted GET request with admin credentials allowing execution of commands with root privileges on the device.

  • CVE-2026-27560HigSep 16, 2026
    risk 0.47cvss 7.2epss 0.03

    A high-privileged remote attacker can exploit a command injection vulnerability in the /api/status/data endpoint by sending a crafted DELETE request with admin credentials allowing execution of commands with root privileges on the device.

  • CVE-2026-27553MedSep 16, 2026
    risk 0.42cvss 6.5epss 0.01

    A low-privileged remote attacker can manipulate the schema path parameter in the /index.php/diagnostics_tab/ajax_diag_table_rows endpoint using a valid user cookie allowing disclosure of all user password hashes.