ZeroHour

Vulnerabilities

4 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2018-5560
A reliance on a static, hard-coded credential in the design of the cloud-based storage system of Practecol's Guardzilla All-In-One Video Security System allows

A reliance on a static, hard-coded credential in the design of the cloud-based storage system of Practecol's Guardzilla All-In-One Video Security System allows an attacker to view the private data of all users of the Guardzilla device.

NVD description · AI analysis pending
7.52% PoC ×2
  • guardzilla gz521w firmware
CVE-2018-18602
The Cloud API on Guardzilla smart cameras allows user enumeration, with resultant arbitrary camera access and monitoring.

The Cloud API on Guardzilla smart cameras allows user enumeration, with resultant arbitrary camera access and monitoring.

NVD description · AI analysis pending
9.81%
  • guardzilla 360 outdoor firmware
  • guardzilla 180 outdoor firmware
  • guardzilla 360 indoor firmware
  • +1 more
CVE-2018-18601
The TK_set_deviceModel_req_handle function in the cloud communication component in Guardzilla GZ621W devices with firmware 0.5.1.4 has a Buffer Overflow.

The TK_set_deviceModel_req_handle function in the cloud communication component in Guardzilla GZ621W devices with firmware 0.5.1.4 has a Buffer Overflow.

NVD description · AI analysis pending
8.11%
  • guardzilla gz621w firmware
CVE-2018-18600
The remote upgrade feature in Guardzilla GZ180 devices allow command injection via a crafted new firmware version parameter.

The remote upgrade feature in Guardzilla GZ180 devices allow command injection via a crafted new firmware version parameter.

NVD description · AI analysis pending
8.12%
  • guardzilla 180 outdoor firmware
  • guardzilla 180 indoor firmware