Vulnerabilities > Guardzilla > High

DATE CVE VULNERABILITY TITLE RISK
2019-01-31 CVE-2018-5560 Use of Hard-coded Credentials vulnerability in Guardzilla Gz521W Firmware
A reliance on a static, hard-coded credential in the design of the cloud-based storage system of Practecol's Guardzilla All-In-One Video Security System allows an attacker to view the private data of all users of the Guardzilla device.
network
low complexity
guardzilla CWE-798
7.5
2018-12-31 CVE-2018-18601 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Guardzilla Gz621W Firmware 0.5.1.4
The TK_set_deviceModel_req_handle function in the cloud communication component in Guardzilla GZ621W devices with firmware 0.5.1.4 has a Buffer Overflow.
network
high complexity
guardzilla CWE-119
8.1
2018-12-31 CVE-2018-18600 OS Command Injection vulnerability in Guardzilla 180 Indoor Firmware and 180 Outdoor Firmware
The remote upgrade feature in Guardzilla GZ180 devices allow command injection via a crafted new firmware version parameter.
network
high complexity
guardzilla CWE-78
8.1