8.8
CVE-2024-2104 - JBL: Improper BLE security configurations and lack of authentication on the device's GATT server
Due to improper BLE security configurations on the device's GATT server, an adjacent unauthenticated attacker can read and write device control commands through the mobile app service wich could render the device unusable.
9.8
CVE-2025-13184 - Unauthenticated Telnet enablement via cstecgi.cgi (auth bypass) leading to unauthenticated root logβ¦
Unauthenticated Telnet enablement via cstecgi.cgi (auth bypass) leading to unauthenticated root login with a blank password on factory/reset X5000R V9.1.0u.6369_B20230113 (arbitrary command execution). Earlier versions that share the same implementation, may also be affected.
9.3
CVE-2025-13953 - Bypass in the authentication method of the GTT Sistema de InformaciΓ³n Tributario application
Bypass vulnerability in the authentication method in the GTT Tax Information System application, related to the Active Directory (LDAP) login method. Authentication is performed through a local WebSocket, but the web application does not properly validate the authenticity or origin of the data recβ¦
8.3
CVE-2025-41358 - Direct reference to insecure objects (IDOR) in CronosWeb from CronosWeb i2A
Direct Object Reference Vulnerability (IDOR) in i2A's CronosWeb, in versions prior to 25.00.00.12, inclusive. This vulnerability could allow an authenticated attacker to access other users' documents by manipulating the βdocumentCodeβ parameter in '/CronosWeb/Modulos/Personas/DocumentosPersonales/Aβ¦
9.8
CVE-2025-41732 - Stack-based buffer overflow via unsafe sscanf in check_cookie()
An unauthenticated remote attacker can abuse unsafe sscanf calls within the check_cookie() function to write arbitrary data into fixed-size stack buffers which leads to full device compromise.
9.8
CVE-2025-41730 - Stack-based buffer overflow via unsafe sscanf in check_account()
An unauthenticated remote attacker can abuse unsafe sscanf calls within the check_account() function to write arbitrary data into fixed-size stack buffers which leads to full device compromise.
0.0
CVE-2025-67689 -
Not used
0.0
CVE-2025-67693 -
Not used
0.0
CVE-2025-67692 -
Not used
0.0
CVE-2025-67691 -
Not used