VYPR
Vendor

dos-osaka

Products
1
CVEs
6
Across products
6
Status
Private

Products

1

Recent CVEs

6
  • CVE-2025-54762CriAug 28, 2025
    risk 0.64cvss 9.8epss 0.00

    SS1 Ver.16.0.0.10 and earlier (Media version:16.0.0a and earlier) allows a remote unauthenticated attacker to upload arbitrary files and execute OS commands with SYSTEM privileges.

  • CVE-2025-53970CriAug 28, 2025
    risk 0.64cvss 9.8epss 0.00

    SS1 Ver.16.0.0.10 and earlier (Media version:16.0.0a and earlier) allows a remote unauthenticated attacker to upload arbitrary files and execute OS commands with SYSTEM privileges.

  • CVE-2025-58072HigAug 28, 2025
    risk 0.49cvss 7.5epss 0.00

    Improper limitation of a pathname to a restricted directory ('Path Traversal') issue exists in SS1 Ver.16.0.0.10 and earlier (Media version:16.0.0a and earlier). If this vulnerability is exploited, arbitrary files may be viewed by a remote unauthenticated attacker.

  • CVE-2025-46409HigAug 28, 2025
    risk 0.49cvss 7.5epss 0.00

    Inadequate encryption strength issue exists in SS1 Ver.16.0.0.10 and earlier (Media version:16.0.0a and earlier). If this vulnerability is exploited, a function that requires authentication may be accessed by a remote unauthenticated attacker.

  • CVE-2025-53396HigAug 28, 2025
    risk 0.46cvss 7.0epss 0.00

    Incorrect permission assignment for critical resource issue exists in SS1 Ver.16.0.0.10 and earlier (Media version:16.0.0a and earlier), which may allow users who can log in to a client terminal to obtain root privileges.

  • CVE-2025-52460MedAug 28, 2025
    risk 0.34cvss 5.3epss 0.00

    Files or directories accessible to external parties issue exists in SS1 Ver.16.0.0.10 and earlier (Media version:16.0.0a and earlier). If exploited, uploaded files and SS1 configuration files may be accessed by a remote unauthenticated attacker.