VYPR
Vendor

Hero

Products
5
CVEs
4
Across products
4
Status
Private

Products

5

Recent CVEs

4
  • CVE-2024-33267CriApr 30, 2024
    risk 0.64cvss 9.8epss 0.01

    SQL Injection vulnerability in Hero hfheropayment v.1.2.5 and before allows an attacker to escalate privileges via the HfHeropaymentGatewayBackModuleFrontController::initContent() function.

  • CVE-2021-37123CriOct 11, 2021
    risk 0.64cvss 9.8epss 0.01

    There is an improper authentication vulnerability in Hero-CT060 before 1.0.0.200. The vulnerability is due to that when an user wants to do certain operation, the software does not insufficiently validate the user's identity. Successful exploit could allow the attacker to do…

  • CVE-2023-22906HigJul 4, 2023
    risk 0.57cvss 8.8epss 0.01

    Hero Qubo HCD01_02_V1.38_20220125 devices allow TELNET access with root privileges by default, without a password.

  • CVE-2008-7162Sep 4, 2009
    risk 0.03cvss epss 0.06

    Buffer overflow in Hero Super Player 3000 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long filename in a .M3U file. NOTE: this might be related to CVE-2008-4504.