VendorsUffiziogps_trackerall versions
Vulnerabilities

Uffizio GPS Tracker

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

5CVEs
CVE-2020-17485
A Remote Code Execution vulnerability exist in Uffizio's GPS Tracker all versions. The web server can be compromised by uploading and executing a web/reverse shell. An attacker could then run commands, browse system files, and browse local resources
Published 2023-12-16 · Modified
9.8EPSS 0.018
CVE-2021-32929
Uffizio GPS Tracker Cross-site Request Forgery
Published 2022-04-22 · Modified
8.8EPSS 0.004
CVE-2020-17483
An improper access control vulnerability exists in Uffizio's GPS Tracker all versions that lead to sensitive information disclosure of all the connected devices. By visiting the vulnerable host at port 9000, we see it responds with a JSON body that has all the details about the devices which have been deployed.
Published 2023-12-16 · Modified
7.5EPSS 0.008
CVE-2021-32927
Uffizio GPS Tracker Cross-site Scripting
Published 2022-04-22 · Modified
7.1EPSS 0.006
CVE-2020-17484
An Open Redirection vulnerability exists in Uffizio's GPS Tracker all versions allows an attacker to construct a URL within the application that causes a redirection to an arbitrary external domain.
Published 2023-12-16 · Modified
6.1EPSS 0.005