Vulnerabilities > Guardzilla

DATE CVE VULNERABILITY TITLE RISK
2019-01-31 CVE-2018-5560 Use of Hard-coded Credentials vulnerability in Guardzilla Gz521W Firmware
A reliance on a static, hard-coded credential in the design of the cloud-based storage system of Practecol's Guardzilla All-In-One Video Security System allows an attacker to view the private data of all users of the Guardzilla device.
network
low complexity
guardzilla CWE-798
7.5
2018-12-31 CVE-2018-18602 Use of Insufficiently Random Values vulnerability in Guardzilla products
The Cloud API on Guardzilla smart cameras allows user enumeration, with resultant arbitrary camera access and monitoring.
network
low complexity
guardzilla CWE-330
critical
9.8
2018-12-31 CVE-2018-18601 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Guardzilla Gz621W Firmware 0.5.1.4
The TK_set_deviceModel_req_handle function in the cloud communication component in Guardzilla GZ621W devices with firmware 0.5.1.4 has a Buffer Overflow.
network
high complexity
guardzilla CWE-119
8.1
2018-12-31 CVE-2018-18600 OS Command Injection vulnerability in Guardzilla 180 Indoor Firmware and 180 Outdoor Firmware
The remote upgrade feature in Guardzilla GZ180 devices allow command injection via a crafted new firmware version parameter.
network
high complexity
guardzilla CWE-78
8.1