VYPR

AVTECH devices

by AVTECH SECURITY Corporation

CVEs (1)

  • CVE-2016-15047HigOct 9, 2025
    risk 0.57cvss epss 0.00

    AVTECH devices that include the CloudSetup.cgi management endpoint are vulnerable to authenticated OS command injection. The `exefile` parameter in CloudSetup.cgi is passed to the underlying system command execution without proper validation or whitelisting. An authenticated…