Vulnerabilities > Easyio

DATE CVE VULNERABILITY TITLE RISK
2020-03-02 CVE-2018-15820 Cross-site Scripting vulnerability in Easyio 30P Firmware 2.0.5.16
EasyIO EasyIO-30P devices before 2.0.5.27 allow XSS via the dev.htm GDN parameter.
network
low complexity
easyio CWE-79
6.1
2020-03-02 CVE-2018-15819 Improper Authentication vulnerability in Easyio 30P Firmware 2.0.5.16
EasyIO EasyIO-30P devices before 2.0.5.27 have Incorrect Access Control, related to webuser.js.
network
low complexity
easyio CWE-287
7.5