Vulnerabilities > Arlo > Vmb3010

DATE CVE VULNERABILITY TITLE RISK
2019-07-09 CVE-2019-3950 Use of Hard-coded Credentials vulnerability in Arlo products
Arlo Basestation firmware 1.12.0.1_27940 and prior contain a hardcoded username and password combination that allows root access to the device when an onboard serial interface is connected to.
network
low complexity
arlo CWE-798
critical
10.0
2019-07-09 CVE-2019-3949 Configuration vulnerability in Arlo products
Arlo Basestation firmware 1.12.0.1_27940 and prior firmware contain a networking misconfiguration that allows access to restricted network interfaces.
network
low complexity
arlo CWE-16
7.5