AirTies Air5341 1.0.0.12 devices allow cgi-bin/login CSRF.
AirTies Air 5453 devices with software 1.0.0.18 have XSS via the top.html productboardtype parameter.
AirTies Air 5443v2 devices with software 1.0.0.18 have XSS via the top.html productboardtype parameter.
AirTies Air 5750 devices with software 1.0.0.18 have XSS via the top.html productboardtype parameter.
AirTies Air 5021 devices with software 1.0.0.18 have XSS via the top.html productboardtype parameter.
AirTies Air 5650 devices with software 1.0.0.18 have XSS via the top.html productboardtype parameter.
AirTies Air 5442 devices with software 1.0.0.18 have XSS via the top.html productboardtype parameter.
AirTies Air 5343v2 devices with software 1.0.0.18 have XSS via the top.html productboardtype parameter.
Airties 5444 1.0.0.18 and 5444TT 1.0.0.18 devices allow XSS.
AirTies Air 4450 1.1.2.18 allows remote attackers to cause a denial of service (reboot) via a direct request to cgi-bin/loader.