Vulnerabilities > Xiongmaitech > Critical

DATE CVE VULNERABILITY TITLE RISK
2022-06-30 CVE-2021-41506 Improper Authentication vulnerability in Xiongmaitech products
Xiaongmai AHB7008T-MH-V2, AHB7804R-ELS, AHB7804R-MH-V2, AHB7808R-MS-V2, AHB7808R-MS, AHB7808T-MS-V2, AHB7804R-LMS, HI3518_50H10L_S39 V4.02.R11.7601.Nat.Onvif.20170420, V4.02.R11.Nat.Onvif.20160422, V4.02.R11.7601.Nat.Onvif.20170424, V4.02.R11.Nat.Onvif.20170327, V4.02.R11.Nat.Onvif.20161205, V4.02.R11.Nat.20170301, V4.02.R12.Nat.OnvifS.20170727 is affected by a backdoor in the macGuarder and dvrHelper binaries of DVR/NVR/IP camera firmware due to static root account credentials in the system.
network
low complexity
xiongmaitech CWE-287
critical
9.8
2018-06-08 CVE-2018-10088 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Xiongmaitech Uc-Httpd 1.0.0
Buffer overflow in XiongMai uc-httpd 1.0.0 has unspecified impact and attack vectors, a different vulnerability than CVE-2017-16725.
network
low complexity
xiongmaitech CWE-119
critical
10.0
2017-12-20 CVE-2017-16725 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Xiongmaitech products
A Stack-based Buffer Overflow issue was discovered in Xiongmai Technology IP Cameras and DVRs using the NetSurveillance Web interface.
network
low complexity
xiongmaitech CWE-119
critical
10.0