Skip to main content

Vendor archive

xiongmaitech CVEs

Beta · best-effort

17 CVEs tagged to vendor xiongmaitech8 Critical, 5 High, 4 Medium, 0 Low, 0 Unrated.

CVE-2018-17919

Published Oct 10, 2018

All versions of Hangzhou Xiongmai Technology Co., Ltd XMeye P2P Cloud Server may allow an attacker to use an undocumented user account "default" with its default password to login…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-17917

Published Oct 10, 2018

All versions of Hangzhou Xiongmai Technology Co., Ltd XMeye P2P Cloud Server may allow an attacker to use MAC addresses to enumerate potential Cloud IDs. Using this ID, the attack…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-17915

Published Oct 10, 2018

All versions of Hangzhou Xiongmai Technology Co., Ltd XMeye P2P Cloud Server do not encrypt all device communication. This includes the XMeye service and firmware update communica…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2018-10088

Published Jun 8, 2018

Buffer overflow in XiongMai uc-httpd 1.0.0 has unspecified impact and attack vectors, a different vulnerability than CVE-2017-16725.

CVSS 9.8 · Critical
evidence mentions
4
Buzz score
24.1
Vendor/product tagsBeta · best-effort

CVE-2017-7577

Published Apr 7, 2017

XiongMai uc-httpd has directory traversal allowing the reading of arbitrary files via a "GET ../" HTTP request.

CVSS 9.8 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort
Showing 1-17 of 17 CVEsPage 1 of 1