VYPR

CTM-200

by Cypress Solutions

CVEs (2)

  • CVE-2021-47745HigDec 31, 2025
    risk 0.57cvss 8.8epss 0.00

    Cypress Solutions CTM-200 2.7.1 contains an authenticated command injection vulnerability in the firmware upgrade script that allows remote attackers to execute shell commands. Attackers can exploit the 'fw_url' parameter in the ctm-config-upgrade.sh script to inject and execute arbitrary commands with root privileges.

  • CVE-2021-47744HigDec 31, 2025
    risk 0.49cvss 7.5epss 0.00

    Cypress Solutions CTM-200/CTM-ONE 1.3.6 contains hard-coded credentials vulnerability in Linux distribution that exposes root access. Attackers can exploit the static 'Chameleon' password to gain remote root access via Telnet or SSH on affected devices.