VYPR
Vendor

Intellian

Products
6
CVEs
8
Across products
9
Status
Private

Products

6

Recent CVEs

8
  • CVE-2020-7980CriJan 25, 2020
    risk 0.73cvss 9.8epss 0.83

    Intellian Aptus Web 1.24 allows remote attackers to execute arbitrary OS commands via the Q field within JSON data to the cgi-bin/libagent.cgi URI. NOTE: a valid sid cookie for a login to the intellian default account might be needed.

  • CVE-2014-0160HigKEVApr 7, 2014
    risk 0.72cvss 7.5epss 1.00

    The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packets, which allows remote attackers to obtain sensitive information from process memory via crafted packets that trigger a buffer over-read, as demonstrated by…

  • CVE-2020-8001CriJan 27, 2020
    risk 0.64cvss 9.8epss 0.02

    The Intellian Aptus application 1.0.2 for Android has a hardcoded password of intellian for the masteruser FTP account.

  • CVE-2020-8000CriJan 27, 2020
    risk 0.64cvss 9.8epss 0.02

    Intellian Aptus Web 1.24 has a hardcoded password of 12345678 for the intellian account.

  • CVE-2020-7999CriJan 27, 2020
    risk 0.64cvss 9.8epss 0.01

    The Intellian Aptus application 1.0.2 for Android has hardcoded values for DOWNLOAD_API_KEY and FILE_DOWNLOAD_API_KEY.

  • CVE-2019-17269CriOct 7, 2019
    risk 0.64cvss 9.8epss 0.03

    Intellian Remote Access 3.18 allows remote attackers to execute arbitrary OS commands via shell metacharacters in the Ping Test field.

  • CVE-2016-6551CriJul 13, 2018
    risk 0.64cvss 9.8epss 0.03

    Intellian Satellite TV antennas t-Series and v-Series, firmware version 1.07, uses non-random default credentials of: ftp/ftp or intellian:12345678. A remote network attacker can gain elevated access to a vulnerable device.

  • CVE-2025-41379MedMay 23, 2025
    risk 0.41cvss epss 0.00

    The Intellian C700 web panel allows you to add firewall rules. Each of these rules has an associated ID, but there is a problem when adding a new rule, the ID used to create the database entry may be different from the JSON ID. If the rule needs to be deleted later, the system…