VYPR

HELO Plus

by AJA

CVEs (1)

  • CVE-2026-47097HigSep 30, 2026
    risk 0.49cvss 7.5epss —

    AJA HELO Plus firmware before 2.1.7 contains an information disclosure vulnerability that allows unauthenticated attackers to decrypt sensitive diagnostics bundles by exploiting a static AES passphrase embedded in obfuscated form within the firmware. Attackers can reverse…