VYPR

SGA1000

by Contec Co., Ltd.

CVEs (3)

  • CVE-2026-82766HigSep 14, 2026
    risk 0.57cvss 8.8epss

    Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in SGA1000. If this vulnerability is exploited, an arbitrary OS command may be executed by an attacker who can log in to the product.

  • CVE-2026-82768HigSep 14, 2026
    risk 0.53cvss 8.1epss

    Path traversal vulnerability exists in SGA1000. If this vulnerability is exploited, arbitrary files on the server may be viewed and/or altered by an attacker who can access the product via FTP.

  • CVE-2026-82767MedSep 14, 2026
    risk 0.34cvss 5.2epss

    Cross-site scripting vulnerability exists in SGA1000. If this vulnerability is exploited, an arbitrary script may be executed on a logged-in user's web browser.