UNIMO Technology Co., Ltd Vulnerabilities and Affected Products
Explore source-attributed vulnerabilities associated with UNIMO Technology Co., Ltd products.
Products
- UDR-JA1604/UDR-JA1608/UDR-JA16163 vulnerabilities
- UNIMO Technology digital video recorders UDR-JA1004/JA1008/JA1016 and UDR-JA10161 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2022-44620HIGH | Improper authentication vulnerability in UDR-JA1604/UDR-JA1608/UDR-JA1616 firmware versions 71x10.1.107112.43A and earlier allows a remote authenticated attacker to execute an arbitrary OS command on the device or alter the device settings. CWE-287Dec 7, 2022 | CVSS8.8v3.1 | EPSS0.866% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2022-44606HIGH | OS command injection vulnerability in UDR-JA1604/UDR-JA1608/UDR-JA1616 firmware versions 71x10.1.107112.43A and earlier allows a remote authenticated attacker to execute an arbitrary OS command on the device or alter the device settings. CWE-78Dec 7, 2022 | CVSS8.8v3.1 | EPSS1.47% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2022-43464HIGH | Hidden functionality vulnerability in UDR-JA1604/UDR-JA1608/UDR-JA1616 firmware versions 71x10.1.107112.43A and earlier allows a remote authenticated attacker to execute an arbitrary OS command on the device or alter the device settings. CWE-78Dec 7, 2022 | CVSS8.8v3.1 | EPSS0.999% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2022-35733CRITICAL | unimo udr-ja1004_firmware Missing Authentication for Critical FunctionMissing authentication for critical function vulnerability in UNIMO Technology digital video recorders (UDR-JA1004/JA1008/JA1016 firmware versions v1.0.20.13 and earlier, and UDR-JA1016 firmware versions v2.0.20.13 and earlier) allows a remote unauthenticated attacker to execute an arbitrary OS command by sending a specially crafted request to the affected device web interface. CWE-306Aug 23, 2022 | CVSS9.8v3.1 | EPSS1.3% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |