Vulnerabilities
Vulnerable Software
Security Vulnerabilities
Incoming VPN network profile settings fail to process special characters safely, enabling command injection via malicious config files.
CVSS Score
8.5
EPSS Score
0.001
Published
2026-06-04
The production build of the M3WebServer hard-codes its backend API keys, which can be easily intercepted through verbose error handling pages.
CVSS Score
9.3
EPSS Score
0.0
Published
2026-06-04
The summary service endpoint suffers from an IDOR vulnerability where it fails to verify user ownership of hardware serial numbers, exposing device data to scraping.
CVSS Score
5.3
EPSS Score
0.0
Published
2026-06-04
Overly permissive configuration settings on cloud storage containers expose active telemetry information publicly to the internet.
CVSS Score
8.7
EPSS Score
0.0
Published
2026-06-04
The debugging routine SCREEN_CLICK(5053) enables a connection to skip the standard device login prompt entirely and directly enter an interactive shell interface.
CVSS Score
9.4
EPSS Score
0.0
Published
2026-06-04
Internal multimedia session archives are accessible without authentication, exacerbated by loose Cross-Origin Resource Sharing (CORS) rules that allow cross-site theft.
CVSS Score
8.8
EPSS Score
0.001
Published
2026-06-04
Crucial management API endpoints for cellular eSIM allocation do not validate caller authorization, allowing remote profiles to be rewritten or deleted.
CVSS Score
7.2
EPSS Score
0.0
Published
2026-06-04
Leftover debug modules contain fixed credentials for internal AWS Cognito test sandboxes, risking asset exploitation.
CVSS Score
6.9
EPSS Score
0.0
Published
2026-06-04
The system fails to evaluate instructional permissions over multiple internal operation codes (opcodes), permitting unauthorized application installations or command executions.
CVSS Score
9.4
EPSS Score
0.001
Published
2026-06-04
libexpat before 2.8.2 lacks handler call depth tracking for calls to XML_GetBuffer, XML_Parse, XML_ParseBuffer, XML_ParserFree, or XML_ParserReset from within handlers in cases of a policy violation. Thus, a use-after-free can occur,
CVSS Score
4.9
EPSS Score
0.0
Published
2026-06-04


Contact Us

Shodan ® - All rights reserved