Vulnerabilities
4 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2018-5560 | A reliance on a static, hard-coded credential in the design of the cloud-based storage system of Practecol's Guardzilla All-In-One Video Security System allows A reliance on a static, hard-coded credential in the design of the cloud-based storage system of Practecol's Guardzilla All-In-One Video Security System allows an attacker to view the private data of all users of the Guardzilla device. NVD description · AI analysis pending | 7.5 | 2% | PoC ×2 |
| — | |
| CVE-2018-18602 | The Cloud API on Guardzilla smart cameras allows user enumeration, with resultant arbitrary camera access and monitoring. The Cloud API on Guardzilla smart cameras allows user enumeration, with resultant arbitrary camera access and monitoring. NVD description · AI analysis pending | 9.8 | 1% |
| — | ||
| CVE-2018-18601 | The TK_set_deviceModel_req_handle function in the cloud communication component in Guardzilla GZ621W devices with firmware 0.5.1.4 has a Buffer Overflow. The TK_set_deviceModel_req_handle function in the cloud communication component in Guardzilla GZ621W devices with firmware 0.5.1.4 has a Buffer Overflow. NVD description · AI analysis pending | 8.1 | 1% |
| — | ||
| CVE-2018-18600 | The remote upgrade feature in Guardzilla GZ180 devices allow command injection via a crafted new firmware version parameter. The remote upgrade feature in Guardzilla GZ180 devices allow command injection via a crafted new firmware version parameter. NVD description · AI analysis pending | 8.1 | 2% |
| — |