VYPR
Vendor

Paradox Security Systems

Products
5
CVEs
4
Across products
6
Status
Private

Products

5

Recent CVEs

4
  • CVE-2020-25189CriNov 21, 2020
    risk 0.64cvss 9.8epss 0.03

    The affected product is vulnerable to three stack-based buffer overflows, which may allow an unauthenticated attacker to remotely execute arbitrary code on the IP150 (firmware versions 5.02.09).

  • CVE-2020-25185HigNov 21, 2020
    risk 0.57cvss 8.8epss 0.02

    The affected product is vulnerable to five post-authentication buffer overflows, which may allow a logged in user to remotely execute arbitrary code on the IP150 (firmware versions 5.02.09).

  • CVE-2023-24709HigMar 21, 2023
    risk 0.55cvss 7.5epss 0.44

    An issue found in Paradox Security Systems IPR512 allows attackers to cause a denial of service via the login.html and login.xml parameters.

  • CVE-2024-5676MedJun 19, 2024
    risk 0.44cvss 6.8epss 0.00

    The Paradox IP150 Internet Module in version 1.40.00 is vulnerable to Cross-Site Request Forgery (CSRF) attacks due to a lack of countermeasures and the use of the HTTP method `GET` to introduce changes in the system.