ZeroHour

Vulnerabilities

19 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2024-58336
+1 in the same advisory: …58337
Akuvox Smart Intercom S539 contains an unauthenticated vulnerability that allows remote attackers to access live video streams by requesting the video.cgi endpo

Akuvox Smart Intercom S539 contains an unauthenticated vulnerability that allows remote attackers to access live video streams by requesting the video.cgi endpoint on port 8080. Attackers can retrieve video stream data without authentication by directly accessing the specified endpoint on affected Akuvox doorphone and intercom devices.

NVD description · AI analysis pending
8.7<1%
  • akuvox s539 firmware
  • akuvox s532 firmware
  • akuvox x916 firmware
  • +1 more
CVE-2023-0344
+1 in the same advisory: …0343
Akuvox E11 appears to be using a custom version of dropbear SSH server.

Akuvox E11 appears to be using a custom version of dropbear SSH server. This server allows an insecure option that by default is not in the official dropbear SSH server.

NVD description · AI analysis pending
7.5<1%
  • akuvox e11 firmware
CVE-2023-0345
The Akuvox E11 secure shell (SSH) server is enabled by default and can be accessed by the root user.

The Akuvox E11 secure shell (SSH) server is enabled by default and can be accessed by the root user. This password cannot be changed by the user.

NVD description · AI analysis pending
9.8
group max
<1%
  • akuvox e11 firmware
CVE-2021-31726
Akuvox C315 115.116.2613 allows remote command Injection via the cfgd_server service.

Akuvox C315 115.116.2613 allows remote command Injection via the cfgd_server service. The attack vector is sending a payload to port 189 (default root 0.0.0.0).

NVD description · AI analysis pending
9.82%
  • akuvox c315 firmware
CVE-2019-12326
+2 in the same advisory: …12327 …12324
Missing file and path validation in the ringtone upload function of the Akuvox R50P VoIP phone 50.0.6.156 allows an attacker to upload a manipulated ringtone fi

Missing file and path validation in the ringtone upload function of the Akuvox R50P VoIP phone 50.0.6.156 allows an attacker to upload a manipulated ringtone file, with an executable payload (shell commands within the file) and trigger code execution.

NVD description · AI analysis pending
9.8
group max
3% PoC
  • akuvox sp-r50p firmware