VYPR

GoIP-1

by Dbltek

CVEs (2)

  • CVE-2017-20204CriOct 15, 2025
    risk 0.61cvss epss 0.01

    DBLTek GoIP devices (models GoIP 1, 4, 8, 16, and 32) contain an undocumented vendor backdoor in the Telnet administrative interface that allows remote authentication as an undocumented user via a proprietary challenge–response scheme which is fundamentally flawed. Because the…

  • CVE-2022-4982HigNov 12, 2025
    risk 0.57cvss epss 0.00

    DBLTek GoIP-1 firmware versions up to and including GHSFVT-1.1-67-5 contain a local file inclusion vulnerability. The device's web server exposes handlers (`frame.html` and `frame.A100.html`) that accept a path parameter (`content` or `sidebar`) which is not properly validated…