VYPR
Vendor

Sapido

Products
10
CVEs
6
Across products
13
Status
Private

Products

10

Recent CVEs

6
  • CVE-2019-25487CriMar 11, 2026
    risk 0.64cvss 9.8epss 0.08

    SAPIDO RB-1732 V2.0.43 contains a remote command execution vulnerability that allows unauthenticated attackers to execute arbitrary system commands by submitting malicious input to the formSysCmd endpoint. Attackers can send POST requests with the sysCmd parameter containing…

  • CVE-2025-6560CriJun 24, 2025
    risk 0.64cvss 9.8epss 0.01

    Multiple wireless router models from Sapido have an Exposure of Sensitive Information vulnerability, allowing unauthenticated remote attackers to directly access a system configuration file and obtain plaintext administrator credentials.  The affected models are out of…

  • CVE-2019-19823HigJan 27, 2020
    risk 0.49cvss 7.5epss 0.06

    A certain router administration interface (that includes Realtek APMIB 0.11f for Boa 0.94.14rc21) stores cleartext administrative passwords in flash memory and in a file. This affects TOTOLINK A3002RU through 2.0.0, A702R through 2.1.3, N301RT through 2.1.6, N302R through 3.4.0,…

  • CVE-2019-19822HigJan 27, 2020
    risk 0.49cvss 7.5epss 0.09

    A certain router administration interface (that includes Realtek APMIB 0.11f for Boa 0.94.14rc21) allows remote attackers to retrieve the configuration, including sensitive data (usernames and passwords). This affects TOTOLINK A3002RU through 2.0.0, A702R through 2.1.3, N301RT…

  • CVE-2021-4242MedNov 30, 2022
    risk 0.41cvss 6.3epss 0.03

    A vulnerability was found in Sapido BR270n, BRC76n, GR297 and RB1732 and classified as critical. Affected by this issue is some unknown functionality of the file ip/syscmd.htm. The manipulation leads to os command injection. The attack may be launched remotely. The exploit has…

  • CVE-2025-7554LowJul 14, 2025
    risk 0.16cvss 2.4epss 0.00

    A vulnerability classified as problematic was found in Sapido RB-1802 1.0.32. This vulnerability affects unknown code of the file urlfilter.asp of the component URL Filtering Page. The manipulation of the argument URL address leads to cross site scripting. The attack can be…