VYPR
Vendor

AUO

Products
3
CVEs
4
Across products
6
Status
Private

Products

3

Recent CVEs

4
  • CVE-2019-12719CriNov 12, 2019
    risk 0.64cvss 9.8epss 0.02

    An issue was discovered in Picture_Manage_mvc.aspx in AUO SunVeillance Monitoring System before v1.1.9e. There is an incorrect access control vulnerability that can allow an unauthenticated user to upload files via a modified authority parameter.

  • CVE-2019-11367CriJun 3, 2019
    risk 0.64cvss 9.8epss 0.03

    An issue was discovered in AUO Solar Data Recorder before 1.3.0. The web portal uses HTTP Basic Authentication and provides the account and password in the WWW-Authenticate attribute. By using this account and password, anyone can login successfully.

  • CVE-2019-12720HigNov 12, 2019
    risk 0.49cvss 7.5epss 0.02

    AUO SunVeillance Monitoring System before v1.1.9e is vulnerable to mvc_send_mail.aspx (MailAdd parameter) SQL Injection. An Attacker can carry a SQL Injection payload to the server, allowing the attacker to read privileged data. This also affects the picture_manage_mvc.aspx…

  • CVE-2019-11368MedJun 3, 2019
    risk 0.38cvss 5.4epss 0.02

    Stored XSS was discovered in AUO Solar Data Recorder before 1.3.0 via the protect/config.htm addr parameter.