Vulnerabilities
19 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2024-58336 +1 in the same advisory: …58337 | Akuvox Smart Intercom S539 contains an unauthenticated vulnerability that allows remote attackers to access live video streams by requesting the video.cgi endpo Akuvox Smart Intercom S539 contains an unauthenticated vulnerability that allows remote attackers to access live video streams by requesting the video.cgi endpoint on port 8080. Attackers can retrieve video stream data without authentication by directly accessing the specified endpoint on affected Akuvox doorphone and intercom devices. NVD description · AI analysis pending | 8.7 | <1% |
| — | ||
| CVE-2023-0344 +1 in the same advisory: …0343 | Akuvox E11 appears to be using a custom version of dropbear SSH server. Akuvox E11 appears to be using a custom version of dropbear SSH server. This server allows an insecure option that by default is not in the official dropbear SSH server. NVD description · AI analysis pending | 7.5 | <1% |
| — | ||
| CVE-2023-0345 | The Akuvox E11 secure shell (SSH) server is enabled by default and can be accessed by the root user. The Akuvox E11 secure shell (SSH) server is enabled by default and can be accessed by the root user. This password cannot be changed by the user. NVD description · AI analysis pending | 9.8 group max | <1% |
| — | ||
| CVE-2021-31726 | Akuvox C315 115.116.2613 allows remote command Injection via the cfgd_server service. Akuvox C315 115.116.2613 allows remote command Injection via the cfgd_server service. The attack vector is sending a payload to port 189 (default root 0.0.0.0). NVD description · AI analysis pending | 9.8 | 2% |
| — | ||
| CVE-2019-12326 | Missing file and path validation in the ringtone upload function of the Akuvox R50P VoIP phone 50.0.6.156 allows an attacker to upload a manipulated ringtone fi Missing file and path validation in the ringtone upload function of the Akuvox R50P VoIP phone 50.0.6.156 allows an attacker to upload a manipulated ringtone file, with an executable payload (shell commands within the file) and trigger code execution. NVD description · AI analysis pending | 9.8 group max | 3% | PoC |
| — |