Vulnerabilities > Guoxinled

DATE CVE VULNERABILITY TITLE RISK
2024-06-16 CVE-2024-38465 Information Exposure Through Discrepancy vulnerability in Guoxinled Synthesis Image System
Shenzhen Guoxin Synthesis image system before 8.3.0 allows username enumeration because of the response discrepancy of incorrect versus error.
network
low complexity
guoxinled CWE-203
5.3
2024-06-16 CVE-2024-38466 Use of Hard-coded Credentials vulnerability in Guoxinled Synthesis Image System
Shenzhen Guoxin Synthesis image system before 8.3.0 has a 123456Qw default password.
network
low complexity
guoxinled CWE-798
critical
9.8
2024-06-16 CVE-2024-38468 Weak Password Recovery Mechanism for Forgotten Password vulnerability in Guoxinled Synthesis Image System
Shenzhen Guoxin Synthesis image system before 8.3.0 allows unauthorized password resets via the resetPassword API.
network
low complexity
guoxinled CWE-640
critical
9.8