VYPR

Csaf

by Cisagov

Source repositories

CVEs (129)

  • CVE-2026-75813HigAug 28, 2026
    risk 0.49cvss 7.5epss 0.00

    Certain configuration endpoints may lack proper server-side authorization checks, allowing unauthorized users to access or modify sensitive device settings. This could result in full compromise of device functionality.

  • CVE-2026-73809HigAug 28, 2026
    risk 0.49cvss 7.5epss 0.00

    A cleartext transmission of sensitive information vulnerability exists in certain Ebyte gateway products. The web management interface does not adequately protect sensitive communications using transport-layer encryption. An attacker with access to network traffic could…

  • CVE-2026-66360HigJul 30, 2026
    risk 0.49cvss 7.5epss 0.00

    The ISO Presentation layer contains a flaw in the handling of specific parameters during normal mode negotiation. A missing length check in the processing of the encoded presentation data allows an attacker controlled field with a zero length value to trigger a bounded heap…

  • CVE-2026-44383HigJul 10, 2026
    risk 0.49cvss 7.5epss 0.01

    Multiple connections to the backend using the same charging station ID are allowed, which could allow an attacker to deploy multiple instances of malicious OCPP clients to overwhelm the backend.

  • CVE-2026-42952HigJul 10, 2026
    risk 0.49cvss 7.5epss 0.01

    Previously, there was no throttling on repeated authentication attempts to the charging station backend, which could allow an attacker to execute a denial-of-service attack.

  • CVE-2026-50176HigJun 25, 2026
    risk 0.49cvss 7.5epss 0.01

    The WebSocket Application Programming Interface lacks restrictions on the number of authentication requests. This absence of rate limiting may allow an attacker to conduct denial-of-service attacks or brute-force attacks to gain unauthorized access.

  • CVE-2026-50108HigJun 12, 2026
    risk 0.49cvss 7.5epss 0.00

    The Naxclow platform API that returns device relay registration details exposes a persistent credential without verifying that the requester is the legitimate device or owner. An actor able to present a platform-valid request signature can retrieve credentials for arbitrary…

  • CVE-2026-25113HigFeb 27, 2026
    risk 0.49cvss 7.5epss 0.00

    The WebSocket Application Programming Interface lacks restrictions on the number of authentication requests. This absence of rate limiting may allow an attacker to conduct denial-of-service attacks by suppressing or mis-routing legitimate charger telemetry, or conduct…

  • CVE-2026-26048HigFeb 20, 2026
    risk 0.49cvss 7.5epss 0.00

    The Wi-Fi router is vulnerable to de-authentication attacks due to the absence of management frame protection, allowing forged deauthentication and disassociation frames to be broadcast without authentication or encryption. An attacker can use this to cause unauthorized…

  • CVE-2026-24455HigFeb 20, 2026
    risk 0.49cvss 7.5epss 0.00

    The embedded web interface of the device does not support HTTPS/TLS for authentication and uses HTTP Basic Authentication. Traffic is encoded but not encrypted, exposing user credentials to passive interception by attackers on the same network.

  • CVE-2025-3232HigDec 24, 2025
    risk 0.49cvss 7.5epss 0.01

    A remote unauthenticated attacker may be able to bypass authentication by utilizing a specific API route to execute arbitrary OS commands.

  • CVE-2025-53704HigDec 4, 2025
    risk 0.49cvss 7.5epss 0.00

    The password reset mechanism for the Pivot client application is weak, and it may allow an attacker to take over the account.

  • CVE-2019-10953HigApr 17, 2019
    risk 0.49cvss 7.5epss 0.03

    ABB, Phoenix Contact, Schneider Electric, Siemens, WAGO - Programmable Logic Controllers, multiple versions. Researchers have found some controllers are susceptible to a denial-of-service attack due to a flood of network packets.

  • CVE-2026-56414HigJun 26, 2026
    risk 0.47cvss 7.2epss 0.00

    A vulnerability exists in H.View IP cameras certificate-related upload interfaces allow authenticated users to store arbitrary file content to fixed, persistent filesystem locations without validating file type, structure, or size. This design omission enables the placement of…

  • CVE-2026-54479HigJun 25, 2026
    risk 0.47cvss 7.3epss 0.00

    The WebSocket backend uses charging station identifiers to uniquely associate sessions but allows multiple endpoints to connect using the same session identifier. This implementation results in predictable session identifiers. This vulnerability may allow unauthorized users to…

  • CVE-2026-6411HigMay 7, 2026
    risk 0.47cvss 7.3epss 0.00

    This vulnerability, in the MAXHUB Pivot client application versions prior to v1.36.2, may allow an attacker to obtain encrypted tenant email addresses and related metadata from any tenant. Due to the presence of a hardcoded AES key within the application, the encrypted data…

  • CVE-2026-90451HigSep 11, 2026
    risk 0.46cvss —epss 0.00

    An example environment-configuration file ships with a fixed, publicly-known secret value used to sign authentication cookies for a bundled packet-analysis component. A deployment that copies this example file into active configuration without running the setup routine that…

  • CVE-2026-61389HigJul 16, 2026
    risk 0.46cvss 7.0epss 0.00

    An out-of-bounds write vulnerability in the Productivity Suite allows a local attacker to trigger kernel memory corruption via a crafted IOCTL request, potentially resulting in privilege escalation or system instability.

  • CVE-2026-60063HigJul 16, 2026
    risk 0.46cvss 7.0epss 0.00

    An out-of-bounds write vulnerability in the Productivity Suite allows a local attacker to trigger kernel memory corruption via a crafted IOCTL request, potentially resulting in privilege escalation or system instability.

  • CVE-2026-33560HigJun 26, 2026
    risk 0.46cvss 7.1epss 0.00

    The DMP-5000 file service exposes authenticated arbitrary file upload functionality. There are exposed endpoints which allows authenticated users to upload files of any type without validation. No file extension filtering or content inspection is enforced which allows executable…

Page 4 of 7