Vulnerabilities
4 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2016-6545 +1 in the same advisory: …6542 | Session cookies are not used for maintaining valid sessions in iTrack Easy. Session cookies are not used for maintaining valid sessions in iTrack Easy. The user's password is passed as a POST parameter over HTTPS using a base64 encoded passwd field on every request. In this implementation, sessions can only be terminated when the user changes the associated password. NVD description · AI analysis pending | 9.8 group max | 3% |
| — | ||
| CVE-2016-6544 +1 in the same advisory: …6543 | getgps data in iTrack Easy can be modified without authentication by setting the data using the parametercmd:setothergps. getgps data in iTrack Easy can be modified without authentication by setting the data using the parametercmd:setothergps. This vulnerability can be exploited to alter the GPS data of a lost device. NVD description · AI analysis pending | 7.5 group max | 3% |
| — |