8.2

CVSS4.0

CVE-2025-64309 - Brightpick Mission Control / Internal Logic Control Unprotected Transport of Credentials

Brightpick Mission Control discloses device telemetry, configuration, and credential information via WebSocket traffic to unauthenticated users when they connect to a specific URL. The unauthenticated URL can be discovered through basic network scanning techniques.

📅 Published: Nov. 14, 2025, 11:41 p.m. 🔄 Last Modified: Nov. 15, 2025, 10:07 p.m.

8.7

CVSS4.0

CVE-2025-64308 - Brightpick Mission Control / Internal Logic Control Unprotected Transport of Credentials

The Brightpick Mission Control web application exposes hardcoded credentials in its client-side JavaScript bundle.

📅 Published: Nov. 14, 2025, 11:38 p.m. 🔄 Last Modified: Nov. 15, 2025, 10:07 p.m.

7.1

CVSS4.0

CVE-2025-64307 - Brightpick Mission Control / Internal Logic Control Missing Authentication for Critical Function

The Brightpick Internal Logic Control web interface is accessible without requiring user authentication. An unauthorized user could exploit this interface to manipulate robot control functions, including initiating or halting runners, assigning jobs, clearing stations, and deploying storage tot…

📅 Published: Nov. 14, 2025, 11:34 p.m. 🔄 Last Modified: Nov. 15, 2025, 10:07 p.m.

8.7

CVSS4.0

CVE-2025-62765 - General Industrial Controls Lynx+ Gateway Cleartext Transmission of Sensitive Information

General Industrial Controls Lynx+ Gateway is vulnerable to a cleartext transmission vulnerability that could allow an attacker to observe network traffic to obtain sensitive information, including plaintext credentials.

📅 Published: Nov. 14, 2025, 11:27 p.m. 🔄 Last Modified: Nov. 15, 2025, 10:07 p.m.

8.7

CVSS4.0

CVE-2025-59780 - General Industrial Controls Lynx+ Gateway Missing Authentication for Critical Function

General Industrial Controls Lynx+ Gateway is missing critical authentication in the embedded web server which could allow an attacker to send GET requests to obtain sensitive device information.

📅 Published: Nov. 14, 2025, 11:26 p.m. 🔄 Last Modified: Nov. 15, 2025, 10:07 p.m.

9.2

CVSS4.0

CVE-2025-58083 - General Industrial Controls Lynx+ Gateway Missing Authentication for Critical Function

General Industrial Controls Lynx+ Gateway  is missing critical authentication in the embedded web server which could allow an attacker to remotely reset the device.

📅 Published: Nov. 14, 2025, 11:24 p.m. 🔄 Last Modified: Nov. 15, 2025, 10:07 p.m.

8.8

CVSS4.0

CVE-2025-55034 - General Industrial Controls Lynx+ Gateway Weak Password Requirements

General Industrial Controls Lynx+ Gateway is vulnerable to a weak password requirement vulnerability, which may allow an attacker to execute a brute-force attack resulting in unauthorized access and login.

📅 Published: Nov. 14, 2025, 11:22 p.m. 🔄 Last Modified: Nov. 15, 2025, 10:07 p.m.

8.7

CVSS4.0

CVE-2021-4469 - Denver SHO-110 IP Camera Unauthenticated Snapshot Access

Denver SHO-110 IP cameras expose a secondary HTTP service on TCP port 8001 that provides access to a '/snapshot' endpoint without authentication. While the primary web interface on port 80 enforces authentication, the backdoor service allows any remote attacker to retrieve image snapshots by direct…

📅 Published: Nov. 14, 2025, 10:53 p.m. 🔄 Last Modified: Nov. 14, 2025, 11:15 p.m.

8.7

CVSS4.0

CVE-2021-4466 - IPCop <= 2.1.9 Authenticated RCE

IPCop versions up to and including 2.1.9 contain an authenticated remote code execution vulnerability within the web-based administration interface. The email configuration component inserts user-controlled values, including the EMAIL_PW parameter, directly into system-level operations without prop…

📅 Published: Nov. 14, 2025, 10:52 p.m. 🔄 Last Modified: Nov. 14, 2025, 11:15 p.m.

8.7

CVSS4.0

CVE-2018-25125 - Netis DL4322D RTK 2.1.1 FTP Service DoS

Netis ADSL Router DL4322D firmware RTK 2.1.1 contains a buffer overflow vulnerability in the embedded FTP service that allows an authenticated remote user to trigger a denial of service. After logging in to the FTP service, sending an FTP command such as ABOR with an excessively long argument cause…

📅 Published: Nov. 14, 2025, 10:52 p.m. 🔄 Last Modified: Nov. 14, 2025, 11:15 p.m.
Total resulsts: 318436
Page 8 of 31,844
« previous page » next page
Filters