VYPR
Vendor

ICP DAS

Products
4
CVEs
3
Across products
5
Status
Private

Products

4

Recent CVEs

3
  • CVE-2019-14551CriAug 3, 2019
    risk 0.64cvss 9.8epss 0.01

    Das Q before 2019-08-02 allows web sites to execute arbitrary code on client machines, as demonstrated by a cross-origin /install request with an attacker-controlled releaseUrl, which triggers download and execution of code within a ZIP archive.

  • CVE-2026-84059HigSep 1, 2026
    risk 0.48cvss 7.4epss

    A flaw has been found in ICP DAS UA-2200 and UA-5200 up to 20260704. The affected element is the function ArmAngstromInstructionSet of the file /CGI?RestApi=SetHostname. Executing a manipulation of the argument ParameterArray can lead to command injection. The attack can be…

  • CVE-2023-4817HigOct 3, 2023
    risk 0.47cvss 7.2epss 0.01

    This vulnerability allows an authenticated attacker to upload malicious files by bypassing the restrictions of the upload functionality, compromising the entire device.