VYPR

Smart Home System CDP-1020n

by Commax

CVEs (3)

  • CVE-2021-47708CriDec 9, 2025
    risk 0.60cvss epss 0.01

    COMMAX Smart Home System CDP-1020n contains an SQL injection vulnerability that allows attackers to bypass authentication by injecting arbitrary SQL code through the 'id' parameter in 'loginstart.asp'. Attackers can exploit this by sending a POST request with malicious 'id'…

  • CVE-2021-47710HigDec 9, 2025
    risk 0.57cvss epss 0.00

    COMMAX Smart Home System is a smart IoT home solution that allows an unauthenticated attacker to disclose RTSP credentials in plain-text by exploiting the /overview.asp endpoint. Attackers can access sensitive information, including login credentials and DVR settings, by…

  • CVE-2021-47709HigDec 9, 2025
    risk 0.57cvss epss 0.00

    COMMAX Smart Home System allows an unauthenticated attacker to change configuration and cause denial-of-service through the setconf endpoint. Attackers can trigger a denial-of-service scenario by sending a malformed request to the setconf endpoint.