VYPR
Vendor

Certvde.com

Products
9
CVEs
6
Across products
6
Status
Private

Products

9

Recent CVEs

6
  • CVE-2026-63586CriAug 25, 2026
    risk 0.64cvss 9.8epss 0.01

    The web-based management interface uses a modified uhttpd server with CGI shell scripts. The HTTP Basic Authentication username, taken directly from the Authorization header without sanitization, is inserted into a shell command string executed via the system() function. By…

  • CVE-2026-35076HigJun 3, 2026
    risk 0.53cvss 8.1epss 0.00

    The bac-scanresult method allows a remote attacker with user privileges to delete arbitrary local files due to insufficient validation of user-controlled input.

  • CVE-2026-14946HigAug 20, 2026
    risk 0.47cvss 7.2epss 0.01

    A high privileged remote attacker can upload a .php file and then request it directly from /uploads/.php to achieve arbitrary code execution due to improper file type validation which could result in full system compromise.

  • CVE-2026-44108CriJul 30, 2026
    risk 0.00cvss 9.8epss 0.01

    Due to a flaw in the execution order of scripts during shutdown, the firewall is terminated prematurely during system shutdown. This creates a temporary window in which internal services may become externally accessible, potentially allowing an unauthenticated remote attacker to…

  • CVE-2026-44098HigJul 30, 2026
    risk 0.00cvss 8.6epss 0.01

    This vulnerability allows an unauthenticated remote attacker with control over the OCPP backend via firewall-bypass to perform an OS command injection, resulting in the execution of arbitrary commands as the limited user charx-oa. Charging could be interrupted.

  • CVE-2026-44096HigJul 30, 2026
    risk 0.00cvss 7.8epss 0.00

    A privilege escalation vulnerability in udhcpc allows a local user "charx-web" to execute arbitrary commands as root, resulting in full system compromise.