Vulnerabilities > Skyworth

DATE CVE VULNERABILITY TITLE RISK
2023-09-20 CVE-2023-40930 Path Traversal vulnerability in Skyworth OS 3.0
An issue in the directory /system/bin/blkid of Skyworth v3.0 allows attackers to perform a directory traversal via mounting the Udisk to /mnt/.
low complexity
skyworth CWE-22
6.8
2021-10-26 CVE-2021-41873 Unspecified vulnerability in Skyworth Penguin Aurora BOX Firmware
Penguin Aurora TV Box 41502 is a high-end network HD set-top box produced by Tencent Video and Skyworth Digital.
network
low complexity
skyworth
6.4
2021-01-14 CVE-2020-26733 Cross-site Scripting vulnerability in Skyworth Gn542Vf Firmware 2.0.0.16
Cross Site Scripting (XSS) in Configuration page in SKYWORTH GN542VF Hardware Version 2.0 and Software Version 2.0.0.16 allows authenticated attacker to inject their own script into the page via DDNS Configuration Section.
network
skyworth CWE-79
3.5
2021-01-14 CVE-2020-26732 Missing Encryption of Sensitive Data vulnerability in Skyworth Gn542Vf BOA Firmware 0.94.13
SKYWORTH GN542VF Boa version 0.94.13 does not set the Secure flag for the session cookie in an HTTPS session, which makes it easier for remote attackers to capture this cookie by intercepting its transmission within an HTTP session.
network
low complexity
skyworth CWE-311
7.5