Vulnerabilities > Winstonprivacy > Critical

DATE CVE VULNERABILITY TITLE RISK
2020-10-28 CVE-2020-16263 Exposure of Resource to Wrong Sphere vulnerability in Winstonprivacy Winston Firmware 1.5.4
Winston 1.5.4 devices have a CORS configuration that trusts arbitrary origins.
network
low complexity
winstonprivacy CWE-668
critical
9.1
2020-10-28 CVE-2020-16259 Unspecified vulnerability in Winstonprivacy Winston Firmware 1.5.4
Winston 1.5.4 devices have an SSH user account with access from bastion hosts.
network
low complexity
winstonprivacy
critical
9.8
2020-10-28 CVE-2020-16257 OS Command Injection vulnerability in Winstonprivacy Winston Firmware 1.5.4
Winston 1.5.4 devices are vulnerable to command injection via the API.
network
low complexity
winstonprivacy CWE-78
critical
9.8