Mohamed Shahat
55 exploits
Active since Feb 2025
GatesAir Maxiva UAXT/VAXT - Info Disclosure
CVSS 8.0
GatesAir Maxiva UAXT/VAXT - Info Disclosure
CVSS 8.0
GatesAir Maxiva UAXT and VAXT - Authenticated Remote Code Execution via /json Endpoint
CVSS 7.2
Electrolink FM/DAB/TV Transmitter - Credentials Disclosure
CVSS 7.5
Orban OPTIMOD 5950 Firmware v1.0.0.2 and System v2.2.15 - Unauthenticated Privilege Escalation to Administrator
CVSS 9.8
JMBroadcast JMB0150 Firmware v1.0 - Use of Hard-coded Credentials
CVSS 9.1
Itel Electronics IP Stream <1.7.0.6 - Privilege Escalation
CVSS 9.1
JMBroadcast JMB0150 Firmware v1.0 - Unauthenticated Admin Panel Access via HOME.php Endpoint
CVSS 9.1
BW Broadcast TX600-1000 - Info Disclosure
CVSS 9.1
Soundcraft Ui Series - Info Disclosure
CVSS 7.5
Nautel VX Series transmitters <6.4.0 - RCE
CVSS 9.8
WorldCast Systems ECRESO FM/DAB/TV Transmitter <1.10.1 - Privilege ...
CVSS 8.8
Elber REBLE310 Firmware <5.5.1.R - Session Hijacking
CVSS 9.8
DAEnetIP4 METO v1.25 - Session Hijacking
CVSS 9.8
2wcom IP-4c 2.16 - Authenticated Remote Code Execution via Ping or Traceroute Field
CVSS 8.8
ENENSYS IPGuard v2 2.10.0 - Use of Hard-coded Credentials
CVSS 9.8
NovelSat NS3000 and NS2000 Firmware - Unauthenticated Session Hijacking via query.fcgi Endpoint
CVSS 9.8
Creacast Creabox Manager 4.4.4 - Unauthenticated Sensitive Information Exposure via /get Endpoint
CVSS 7.5
Sound4 PULSE-ECO AES67 Firmware 1.22 - Remote Code Execution via Malicious Firmware Update Package
CVSS 8.8
Blackmagic Web Presenter 3.3 - Unauthenticated Remote Command Execution via Telnet Service
CVSS 9.8
2wcom IP-4c 2.15.5 - Authenticated Exposure of Sensitive Information via /cwi/ajax_request/get_data.php
CVSS 6.5
Creacast Creabox Manager - Improper Authentication via Password Prefix Bypass
CVSS 8.8
Blackmagic Web Presenter HD Firmware 3.3 - Unauthenticated Sensitive Information Exposure via Telnet Service
CVSS 9.8
2wcom IP-4c 2.15.5 - Broken Access Control via Request Manipulation
CVSS 6.8
Creacast Creabox Manager 4.4.4 - Authenticated Remote Code Execution via edit.php Lua Injection
CVSS 8.8