assaabloy records
19 published records for vendor assaabloy.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 2
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')3
- CWE-326 Inadequate Encryption Strength3
- CWE-287 Improper Authentication1
- CWE-312 Cleartext Storage of Sensitive Information1
- CWE-327 Use of a Broken or Risky Cryptographic Algorithm1
- CWE-668 Exposure of Resource to Wrong Sphere1
The weakness classes this vendor ships most often: where to look.
CWEBug bounty scope
The product’s vendor appears in a public program. Matched by name; verify the scope text in the program.
All records
19 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
40Plan | CVE-2020-10176No exploit | ASSA ABLOY Yale WIPC-301W 2.x.2.29 through 2.x.2.43_p1 devices allow Eval Injection of commands.assaabloy · yale wipc-301w firmware · CWE-94 | Critical9.8 | — | 2.3% | May 7, 2020 |
39Monitor | CVE-2020-23826No exploit | The Yale WIPC-303W 2.21 through 2.31 camera is vulnerable to remote command execution (RCE) through command injection via the HTTP API.assaabloy · yale wipc-303w firmware · CWE-78 | High8.8 | — | 12.6% | Jan 26, 2021 |
39Monitor | CVE-2023-33367No exploit | A SQL injection vulnerability exists in Control ID IDSecure 4.7.26.0 and prior, allowing unauthenticated attackers to write PHP files on theassaabloy · control id idsecure · CWE-89 | Critical9.8 | — | 1.1% | Aug 4, 2023 |
39Monitor | CVE-2023-33371No exploit | Control ID IDSecure 4.7.26.0 and prior uses a hardcoded cryptographic key in order to sign and verify JWT session tokens, allowing attackersassaabloy · control id idsecure · CWE-798 | Critical9.8 | — | 0.9% | Aug 2, 2023 |
39Monitor | CVE-2023-2043No exploit | Control iD RHiD Edit a sql injectionassaabloy · control id rhid · CWE-89 | Critical9.8 | — | 0.5% | Apr 14, 2023 |
37Monitor | CVE-2025-49853No exploit | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') in ControlID iDSecure On-premisesassaabloy · control id idsecure · CWE-89 | Critical9.3 | — | 0.5% | Jun 24, 2025 |
36Monitor | CVE-2023-33369No exploit | A path traversal vulnerability exists in Control ID IDSecure 4.7.26.0 and prior, allowing attackers to delete arbitrary files on IDSecure fiassaabloy · control id idsecure · CWE-22 | Critical9.1 | — | 0.7% | Aug 2, 2023 |
34Monitor | CVE-2025-49851No exploit | Improper Authentication in ControlID iDSecure On-premisesassaabloy · control id idsecure · CWE-287 | High8.7 | — | 0.6% | Jun 24, 2025 |
34Monitor | CVE-2025-49852No exploit | Server-Side Request Forgery (SSRF) in ControlID iDSecure On-premisesassaabloy · control id idsecure · CWE-918 | High8.7 | — | 0.4% | Jun 24, 2025 |
30Monitor | CVE-2023-33370No exploit | An uncaught exception vulnerability exists in Control ID IDSecure 4.7.26.0 and prior, allowing attackers to cause the main web server of IDSassaabloy · control id idsecure · CWE-755 | High7.5 | — | 0.6% | Aug 2, 2023 |
26Monitor | CVE-2023-33368No exploit | Some API routes exists in Control ID IDSecure 4.7.26.0 and prior, exfiltrating sensitive information and passwords to users accessing these assaabloy · control id idsecure · CWE-668 | Medium6.5 | — | 0.5% | Aug 2, 2023 |
26Monitor | CVE-2023-26943No exploit | Weak encryption mechanisms in RFID Tags in Yale Keyless Lock v1.0 allows attackers to create a cloned tag via physical proximity to the origassaabloy · yale keyless smart lock firmware · CWE-326 | Medium6.5 | — | 0.2% | Dec 4, 2023 |
26Monitor | CVE-2023-26942No exploit | Weak encryption mechanisms in RFID Tags in Yale IA-210 Alarm v1.0 allows attackers to create a cloned tag via physical proximity to the origassaabloy · yale ia-210 firmware · CWE-326 | Medium6.5 | — | 0.2% | Dec 4, 2023 |
26Monitor | CVE-2023-26941No exploit | Weak encryption mechanisms in RFID Tags in Yale Conexis L1 v1.1.0 allows attackers to create a cloned tag via physical proximity to the origassaabloy · yale conexis l1 firmware · CWE-326 | Medium6.5 | — | 0.2% | Dec 4, 2023 |
24Monitor | CVE-2023-2044No exploit | Control iD iDSecure Dispositivos Page cross site scriptingassaabloy · control id idsecure · CWE-79 | Medium6.1 | — | 0.4% | Apr 14, 2023 |
23Monitor | CVE-2019-13604No exploit | There is a short key vulnerability in HID Global DigitalPersona (formerly Crossmatch) U.are.U 4500 Fingerprint Reader v24.assaabloy · hid digitalpersona 4500 firmware · CWE-327 | Medium5.9 | — | 1.1% | Jul 15, 2019 |
23Monitor | CVE-2026-3315No exploit | Local Privilege Escalation Due to Writable Executable in Privileged Visionline Service Pathassaabloy · visionline · CWE-250 | Medium5.8 | — | 0.2% | Mar 10, 2026 |
21Monitor | CVE-2023-4392No exploit | Control iD Gerencia Web Cookie cleartext storageassaabloy · control id gerencia web · CWE-312 | Medium5.3 | — | 0.6% | Aug 16, 2023 |
21Monitor | CVE-2025-2125No exploit | Control iD RH iD PDF Document companyId resource injectionassaabloy · control id rhid · CWE-99 | Medium5.3 | — | 0.3% | Mar 9, 2025 |
- CVE-2020-1017640Plan
ASSA ABLOY Yale WIPC-301W 2.x.2.29 through 2.x.2.43_p1 devices allow Eval Injection of commands.
CriticalCVSS 9.8No exploitEPSS 2%assaabloy · yale wipc-301w firmwareMay 7, 2020
- CVE-2020-2382639Monitor
The Yale WIPC-303W 2.21 through 2.31 camera is vulnerable to remote command execution (RCE) through command injection via the HTTP API.
HighCVSS 8.8No exploitEPSS 13%assaabloy · yale wipc-303w firmwareJan 26, 2021
- CVE-2023-3336739Monitor
A SQL injection vulnerability exists in Control ID IDSecure 4.7.26.0 and prior, allowing unauthenticated attackers to write PHP files on the
CriticalCVSS 9.8No exploitEPSS 1%assaabloy · control id idsecureAug 4, 2023
- CVE-2023-3337139Monitor
Control ID IDSecure 4.7.26.0 and prior uses a hardcoded cryptographic key in order to sign and verify JWT session tokens, allowing attackers
CriticalCVSS 9.8No exploitEPSS 1%assaabloy · control id idsecureAug 2, 2023
- CVE-2023-204339Monitor
Control iD RHiD Edit a sql injection
CriticalCVSS 9.8No exploitEPSS 1%assaabloy · control id rhidApr 14, 2023
- CVE-2025-4985337Monitor
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') in ControlID iDSecure On-premises
CriticalCVSS 9.3No exploitEPSS 0%assaabloy · control id idsecureJun 24, 2025
- CVE-2023-3336936Monitor
A path traversal vulnerability exists in Control ID IDSecure 4.7.26.0 and prior, allowing attackers to delete arbitrary files on IDSecure fi
CriticalCVSS 9.1No exploitEPSS 1%assaabloy · control id idsecureAug 2, 2023
- CVE-2025-4985134Monitor
Improper Authentication in ControlID iDSecure On-premises
HighCVSS 8.7No exploitEPSS 1%assaabloy · control id idsecureJun 24, 2025
- CVE-2025-4985234Monitor
Server-Side Request Forgery (SSRF) in ControlID iDSecure On-premises
HighCVSS 8.7No exploitEPSS 0%assaabloy · control id idsecureJun 24, 2025
- CVE-2023-3337030Monitor
An uncaught exception vulnerability exists in Control ID IDSecure 4.7.26.0 and prior, allowing attackers to cause the main web server of IDS
HighCVSS 7.5No exploitEPSS 1%assaabloy · control id idsecureAug 2, 2023
- CVE-2023-3336826Monitor
Some API routes exists in Control ID IDSecure 4.7.26.0 and prior, exfiltrating sensitive information and passwords to users accessing these
MediumCVSS 6.5No exploitEPSS 1%assaabloy · control id idsecureAug 2, 2023
- CVE-2023-2694326Monitor
Weak encryption mechanisms in RFID Tags in Yale Keyless Lock v1.0 allows attackers to create a cloned tag via physical proximity to the orig
MediumCVSS 6.5No exploitEPSS 0%assaabloy · yale keyless smart lock firmwareDec 4, 2023
- CVE-2023-2694226Monitor
Weak encryption mechanisms in RFID Tags in Yale IA-210 Alarm v1.0 allows attackers to create a cloned tag via physical proximity to the orig
MediumCVSS 6.5No exploitEPSS 0%assaabloy · yale ia-210 firmwareDec 4, 2023
- CVE-2023-2694126Monitor
Weak encryption mechanisms in RFID Tags in Yale Conexis L1 v1.1.0 allows attackers to create a cloned tag via physical proximity to the orig
MediumCVSS 6.5No exploitEPSS 0%assaabloy · yale conexis l1 firmwareDec 4, 2023
- CVE-2023-204424Monitor
Control iD iDSecure Dispositivos Page cross site scripting
MediumCVSS 6.1No exploitEPSS 0%assaabloy · control id idsecureApr 14, 2023
- CVE-2019-1360423Monitor
There is a short key vulnerability in HID Global DigitalPersona (formerly Crossmatch) U.are.U 4500 Fingerprint Reader v24.
MediumCVSS 5.9No exploitEPSS 1%assaabloy · hid digitalpersona 4500 firmwareJul 15, 2019
- CVE-2026-331523Monitor
Local Privilege Escalation Due to Writable Executable in Privileged Visionline Service Path
MediumCVSS 5.8No exploitEPSS 0%assaabloy · visionlineMar 10, 2026
- CVE-2023-439221Monitor
Control iD Gerencia Web Cookie cleartext storage
MediumCVSS 5.3No exploitEPSS 1%assaabloy · control id gerencia webAug 16, 2023
- CVE-2025-212521Monitor
Control iD RH iD PDF Document companyId resource injection
MediumCVSS 5.3No exploitEPSS 0%assaabloy · control id rhidMar 9, 2025