Micodus
Micodus Mv720 Firmware: vulnerabilidades y CVE
Micodus Mv720 Firmware tiene 5 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 2 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE5
Últimos 12 meses0
Críticas2
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2022-34150 | Media (5.4) | 0.70% | — | 20 jul 2022 | The main MiCODUS MV720 GPS tracker web server has an authenticated insecure direct object reference vulnerability on endpoint and parameter device IDs, which accept arbitrary device IDs without further verification. |
| CVE-2022-33944 | Media (6.5) | 0.97% | — | 20 jul 2022 | The main MiCODUS MV720 GPS tracker web server has an authenticated insecure direct object references vulnerability on endpoint and POST parameter “Device ID,” which accepts arbitrary device IDs. |
| CVE-2022-2199 | Media (6.1) | 0.69% | — | 20 jul 2022 | The main MiCODUS MV720 GPS tracker web server has a reflected cross-site scripting vulnerability that could allow an attacker to gain control by tricking a user into making a request. |
| CVE-2022-2141 | Crítica (9.8) | 1.3% | — | 20 jul 2022 | SMS-based GPS commands can be executed by MiCODUS MV720 GPS tracker without authentication. |
| CVE-2022-2107 | Crítica (9.8) | 1.3% | — | 20 jul 2022 | The MiCODUS MV720 GPS tracker API server has an authentication mechanism that allows devices to use a hard-coded master password. This may allow an attacker to send SMS commands directly to the GPS tracker as if they… |