VendorsiSmartAlarmcubeone_firmwareall versions
Vulnerabilities

iSmartAlarm CubeOne

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

7CVEs
CVE-2017-7728
On iSmartAlarm cube devices, there is authentication bypass leading to remote execution of commands (e.g., setting the alarm on/off), related to incorrect cryptography.
Published 2017-07-11 · Modified
9.8EPSS 0.035
CVE-2017-13664
Password file exposure in firmware in iSmartAlarm CubeOne version 2.2.4.8 and earlier allows attackers to execute arbitrary commands with administrative privileges by retrieving credentials from this file.
Published 2017-12-01 · Modified
9.8EPSS 0.015
CVE-2017-7730
iSmartAlarm cube devices allow Denial of Service. Sending a SYN flood on port 12345 will freeze the "cube" and it will stop responding.
Published 2017-07-11 · Modified
7.8EPSS 0.013
CVE-2017-7726
iSmartAlarm cube devices have an SSL Certificate Validation Vulnerability.
Published 2017-07-11 · Modified
7.5EPSS 0.007
CVE-2017-7729
On iSmartAlarm cube devices, there is Incorrect Access Control because a "new key" is transmitted in cleartext.
Published 2017-07-11 · Modified
7.5EPSS 0.007
CVE-2017-13663
Encryption key exposure in firmware in iSmartAlarm CubeOne version 2.2.4.8 and earlier allows attackers to decrypt log files via an exposed key.
Published 2017-12-01 · Modified
7.5EPSS 0.004
CVE-2018-16224
Incorrect access control for the diagnostic files of the iSmartAlarm Cube One through 2.2.4.10 allows an attacker to retrieve them via a specifically crafted TCP request to port 12345 and 22306, and access sensitive information from the device.
Published 2018-11-20 · Modified
5.3EPSS 0.066