Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
MEDIUM 5.3
CVE-2024-58336
Akuvox Smart Intercom S539 contains an unauthenticated vulnerability that allows remote attackers to access live video streams by requesting the vide…
S539 Firmware
No fix yet
HIGH 7.5
CVE-2023-0343
Akuvox E11 contains a function that encrypts messages which are then forwarded. The IV vector and the key are static, and this may allow an attacker …
E11 Firmware
Mitigation only
HIGH 7.5
CVE-2023-0344
Akuvox E11 appears to be using a custom version of dropbear SSH server. This server allows an insecure option that by default is not in the official …
E11 Firmware
Mitigation only
CRITICAL 9.8
CVE-2023-0345
The Akuvox E11 secure shell (SSH) server is enabled by default and can be accessed by the root user. This password cannot be changed by the user.
E11 Firmware
Mitigation only
CRITICAL 9.8
CVE-2023-0353
Akuvox E11 uses a weak encryption algorithm for stored passwords and uses a hard-coded password for decryption which could allow the encrypted passwo…
E11 Firmware
Mitigation only
CRITICAL 9.1
CVE-2023-0349
The Akuvox E11 libvoice library provides unauthenticated access to the camera capture for image and video. This could allow an attacker to view and r…
E11 Firmware
Mitigation only
CRITICAL 9.1
CVE-2023-0352
The Akuvox E11 password recovery webpage can be accessed without authentication, and an attacker could download the device key file. An attacker coul…
E11 Firmware
Mitigation only
CRITICAL 9.1
CVE-2023-0354
The Akuvox E11 web server can be accessed without any user authentication, and this could allow an attacker to access sensitive information, as well …
E11 Firmware
Mitigation only
HIGH 8.8
CVE-2023-0351
The Akuvox E11 web server backend library allows command injection in the device phone-book contacts functionality. This could allow an attacker to u…
E11 Firmware
Mitigation only
HIGH 7.5
CVE-2023-0346
Akuvox E11 cloud login is performed through an unencrypted HTTP connection. An attacker could gain access to the Akuvox cloud and device if the MAC a…
E11 Firmware
Mitigation only
HIGH 7.5
CVE-2023-0348
Akuvox E11 allows direct SIP calls. No access control is enforced by the SIP servers, which could allow an attacker to contact any device within Akuv…
E11 Firmware
Mitigation only
MEDIUM 6.5
CVE-2023-0350
Akuvox E11 does not ensure that a file extension is associated with the file provided. This could allow an attacker to upload a file to the device by…
E11 Firmware
Mitigation only
MEDIUM 5.3
CVE-2023-0347
The Akuvox E11 Media Access Control (MAC) address, a primary identifier, combined with the Akuvox E11 IP address, could allow an attacker to identify…
E11 Firmware
Mitigation only
HIGH 7.5
CVE-2023-0355
Akuvox E11 uses a hard-coded cryptographic key, which could allow an attacker to decrypt sensitive information.
E11 Firmware
Mitigation only
CRITICAL 9.8
CVE-2021-31726
Akuvox C315 115.116.2613 allows remote command Injection via the cfgd_server service. The attack vector is sending a payload to port 189 (default roo…
C315 Firmware
Mitigation only
CRITICAL 9.8
CVE-2019-12327
Hardcoded credentials in the Akuvox R50P VoIP phone 50.0.6.156 allow an attacker to get access to the device via telnet. The telnet service is runnin…
Sp R50p Firmware
No fix yet
CRITICAL 9.8
CVE-2019-12326
Missing file and path validation in the ringtone upload function of the Akuvox R50P VoIP phone 50.0.6.156 allows an attacker to upload a manipulated …
Sp R50p Firmware
No fix yet
HIGH 7.2
CVE-2019-12324
A command injection (missing input validation) issue in the IP address field for the logging server in the configuration web interface on the Akuvox …
Sp R50p Firmware
No fix yet