Skip to main content

Vendor archive

changingtec CVEs

Beta · best-effort

22 CVEs tagged to vendor changingtec4 Critical, 10 High, 8 Medium, 0 Low, 0 Unrated.

CVE-2026-3000

Published Mar 2, 2026

IDExpert Windows Logon Agent developed by Changing has a Remote Code Execution vulnerability, allowing unauthenticated remote attackers to force the system to download arbitrary D…

CVSS 9.3 · Critical
evidence mentions
3
Buzz score
23.9
Vendor/product tagsBeta · best-effort

CVE-2026-2999

Published Mar 2, 2026

IDExpert Windows Logon Agent developed by Changing has a Remote Code Execution vulnerability, allowing unauthenticated remote attackers to force the system to download arbitrary e…

CVSS 9.3 · Critical
evidence mentions
3
Buzz score
23.9
Vendor/product tagsBeta · best-effort

CVE-2024-40723

Published Aug 2, 2024

The specific API in HWATAIServiSign Windows Version from CHANGING Information Technology does not properly validate the length of server-side inputs. When a user visits a spoofed…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-40722

Published Aug 2, 2024

The specific API in TCBServiSign Windows Version from CHANGING Information Technology does does not properly validate the length of server-side input. When a user visits a spoofed…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-40721

Published Aug 2, 2024

The specific API in TCBServiSign Windows Version from CHANGING Information Technology does not properly validate server-side input. When a user visits a spoofed website, unauthent…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2024-40720

Published Aug 2, 2024

The specific API in TCBServiSign Windows Version from CHANGING Information Technology does not properly validate server-side input. When a user visits a spoofed website, unauthent…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2024-40719

Published Aug 2, 2024

The encryption strength of the authorization keys in CHANGING Information Technology TCBServiSign Windows Version is insufficient. When a remote attacker tricks a victim into visi…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-22901

Published Apr 27, 2023

ChangingTec MOTP system has a path traversal vulnerability. A remote attacker with administrator’s privilege can exploit this vulnerability to access arbitrary system files.

CVSS 4.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-39061

Published Jan 31, 2023

ChangingTech MegaServiSignAdapter component has a vulnerability of Out-of-bounds Read due to insufficient validation for parameter length. An unauthenticated remote attacker can e…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-39060

Published Jan 31, 2023

ChangingTech MegaServiSignAdapter component has a vulnerability of improper input validation. An unauthenticated remote attacker can exploit this vulnerability to access and modif…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2022-39059

Published Jan 31, 2023

ChangingTech MegaServiSignAdapter component has a path traversal vulnerability within its file reading function. An unauthenticated remote attacker can exploit this vulnerability…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2022-46306

Published Jan 3, 2023

ChangingTec ServiSign component has a path traversal vulnerability due to insufficient filtering for special characters in the DLL file path. An unauthenticated remote attacker ca…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2022-46305

Published Jan 3, 2023

ChangingTec ServiSign component has a path traversal vulnerability. An unauthenticated LAN attacker can exploit this vulnerability to bypass authentication and access arbitrary sy…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-46304

Published Jan 3, 2023

ChangingTec ServiSign component has insufficient filtering for special characters in the connection response parameter. An unauthenticated remote attacker can host a malicious web…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2021-44161

Published Dec 29, 2021

Changing MOTP (Mobile One Time Password) system’s specific function parameter has insufficient validation for user input. A attacker in local area network can perform SQL injectio…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2020-3927

Published Feb 3, 2020

An arbitrary-file-access vulnerability exists in ServiSign security plugin, as long as the attackers learn the specific API function, they may access arbitrary files on target sys…

CVSS 8.3 · High
Vendor/product tagsBeta · best-effort

CVE-2020-3926

Published Feb 3, 2020

An arbitrary-file-access vulnerability exists in ServiSign security plugin, as long as the attackers learn the specific API function, they may access arbitrary files on target sys…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-3925

Published Feb 3, 2020

A Remote Code Execution(RCE) vulnerability exists in some designated applications in ServiSign security plugin, as long as the interface is captured, attackers are able to launch…

CVSS 8.3 · High
Vendor/product tagsBeta · best-effort
Showing 1-22 of 22 CVEsPage 1 of 1