ZeroHour

Vulnerabilities

8 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2025-44039
CP-XR-DE21-S -4G Router Firmware version 1.031.022 was discovered to contain insecure protections for its UART console.

CP-XR-DE21-S -4G Router Firmware version 1.031.022 was discovered to contain insecure protections for its UART console. This vulnerability allows local attackers to connect to the UART port via a serial connection, read all boot sequence, and revealing internal system details and sensitive information without any authentication.

NVD description · AI analysis pending
5.1<1% PoC
  • cpplusworld cp-xr-de21-s firmware
CVE-2024-54848
+3 in the same advisory: …54847 …54846 …54849
Improper handling and storage of certificates in CP Plus CP-VNR-3104 B3223P22C02424 allow attackers to decrypt communications or execute a man-in-the-middle att

Improper handling and storage of certificates in CP Plus CP-VNR-3104 B3223P22C02424 allow attackers to decrypt communications or execute a man-in-the-middle attacks.

NVD description · AI analysis pending
7.4
group max
<1% PoC
  • cpplusworld cp-vnr-3104 firmware
CVE-2023-3705
The vulnerability exists in CP-Plus NVR due to an improper input handling at the web-based management interface of the affected product.

The vulnerability exists in CP-Plus NVR due to an improper input handling at the web-based management interface of the affected product. An unauthenticated remote attacker could exploit this vulnerability by sending specially crafted HTTP requests to the vulnerable device. Successful exploitation of this vulnerability could allow the remote attacker to obtain sensitive information on the targeted device.

NVD description · AI analysis pending
7.51%
  • cpplusworld cp-vnr-3104 firmware
  • cpplusworld cp-vnr-3108 firmware
  • cpplusworld cp-vnr-3208 firmware
CVE-2023-3704
The vulnerability exists in CP-Plus DVR due to an improper input validation within the web-based management interface of the affected products.

The vulnerability exists in CP-Plus DVR due to an improper input validation within the web-based management interface of the affected products. An unauthenticated remote attacker could exploit this vulnerability by sending specially crafted HTTP requests to the vulnerable device. Successful exploitation of this vulnerability could allow the remote attacker to change system time of the targeted device.

NVD description · AI analysis pending
5.3<1%
  • cpplusworld cp-uvr-1601e1-hc firmware
  • cpplusworld cp-uvr-0401l1-4kh firmware
  • cpplusworld cp-uvr-0401l1b-4kh firmware
  • +1 more
CVE-2023-1518
CP Plus KVMS Pro versions 2.01.0.T.190521 and prior are vulnerable to sensitive credentials being leaked because they are insufficiently protected.

CP Plus KVMS Pro versions 2.01.0.T.190521 and prior are vulnerable to sensitive credentials being leaked because they are insufficiently protected.

NVD description · AI analysis pending
7.5<1%
  • cpplusworld kvms pro