Skip to main content

Vendor/product archive

micodus / mv720_firmware CVEs

Beta · best-effort

5 CVEs tagged to micodus / mv720_firmware2 Critical, 2 High, 1 Medium, 0 Low, 0 Unrated.

CVE-2022-34150

Published Jul 20, 2022

The main MiCODUS MV720 GPS tracker web server has an authenticated insecure direct object reference vulnerability on endpoint and parameter device IDs, which accept arbitrary devi…

CVSS 7.1 · High
evidence mentions
4
Buzz score
25.6
Vendor/product tagsBeta · best-effort

CVE-2022-33944

Published Jul 20, 2022

The main MiCODUS MV720 GPS tracker web server has an authenticated insecure direct object references vulnerability on endpoint and POST parameter “Device ID,” which accepts arbitr…

CVSS 6.5 · Medium
evidence mentions
4
Buzz score
25.6
Vendor/product tagsBeta · best-effort

CVE-2022-2199

Published Jul 20, 2022

The main MiCODUS MV720 GPS tracker web server has a reflected cross-site scripting vulnerability that could allow an attacker to gain control by tricking a user into making a requ…

CVSS 7.5 · High
evidence mentions
4
Buzz score
25.6
Vendor/product tagsBeta · best-effort

CVE-2022-2107

Published Jul 20, 2022

The MiCODUS MV720 GPS tracker API server has an authentication mechanism that allows devices to use a hard-coded master password. This may allow an attacker to send SMS commands d…

CVSS 9.8 · Critical
evidence mentions
4
Buzz score
25.6
Vendor/product tagsBeta · best-effort
Showing 1-5 of 5 CVEsPage 1 of 1