Skip to content
Noroxi

assaabloy records

19 published records for vendor assaabloy.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
2
With a fix record
0%
Median publish → KEV
No record has entered KEV

Bug bounty scope

The product’s vendor appears in a public program. Matched by name; verify the scope text in the program.

All records

19 records
  • ASSA ABLOY Yale WIPC-301W 2.x.2.29 through 2.x.2.43_p1 devices allow Eval Injection of commands.

    CriticalCVSS 9.8No exploitEPSS 2%

    assaabloy · yale wipc-301w firmwareMay 7, 2020

  • The Yale WIPC-303W 2.21 through 2.31 camera is vulnerable to remote command execution (RCE) through command injection via the HTTP API.

    HighCVSS 8.8No exploitEPSS 13%

    assaabloy · yale wipc-303w firmwareJan 26, 2021

  • A SQL injection vulnerability exists in Control ID IDSecure 4.7.26.0 and prior, allowing unauthenticated attackers to write PHP files on the

    CriticalCVSS 9.8No exploitEPSS 1%

    assaabloy · control id idsecureAug 4, 2023

  • Control ID IDSecure 4.7.26.0 and prior uses a hardcoded cryptographic key in order to sign and verify JWT session tokens, allowing attackers

    CriticalCVSS 9.8No exploitEPSS 1%

    assaabloy · control id idsecureAug 2, 2023

  • CVE-2023-2043
    39Monitor

    Control iD RHiD Edit a sql injection

    CriticalCVSS 9.8No exploitEPSS 1%

    assaabloy · control id rhidApr 14, 2023

  • Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') in ControlID iDSecure On-premises

    CriticalCVSS 9.3No exploitEPSS 0%

    assaabloy · control id idsecureJun 24, 2025

  • A path traversal vulnerability exists in Control ID IDSecure 4.7.26.0 and prior, allowing attackers to delete arbitrary files on IDSecure fi

    CriticalCVSS 9.1No exploitEPSS 1%

    assaabloy · control id idsecureAug 2, 2023

  • Improper Authentication in ControlID iDSecure On-premises

    HighCVSS 8.7No exploitEPSS 1%

    assaabloy · control id idsecureJun 24, 2025

  • Server-Side Request Forgery (SSRF) in ControlID iDSecure On-premises

    HighCVSS 8.7No exploitEPSS 0%

    assaabloy · control id idsecureJun 24, 2025

  • An uncaught exception vulnerability exists in Control ID IDSecure 4.7.26.0 and prior, allowing attackers to cause the main web server of IDS

    HighCVSS 7.5No exploitEPSS 1%

    assaabloy · control id idsecureAug 2, 2023

  • Some API routes exists in Control ID IDSecure 4.7.26.0 and prior, exfiltrating sensitive information and passwords to users accessing these

    MediumCVSS 6.5No exploitEPSS 1%

    assaabloy · control id idsecureAug 2, 2023

  • Weak encryption mechanisms in RFID Tags in Yale Keyless Lock v1.0 allows attackers to create a cloned tag via physical proximity to the orig

    MediumCVSS 6.5No exploitEPSS 0%

    assaabloy · yale keyless smart lock firmwareDec 4, 2023

  • Weak encryption mechanisms in RFID Tags in Yale IA-210 Alarm v1.0 allows attackers to create a cloned tag via physical proximity to the orig

    MediumCVSS 6.5No exploitEPSS 0%

    assaabloy · yale ia-210 firmwareDec 4, 2023

  • Weak encryption mechanisms in RFID Tags in Yale Conexis L1 v1.1.0 allows attackers to create a cloned tag via physical proximity to the orig

    MediumCVSS 6.5No exploitEPSS 0%

    assaabloy · yale conexis l1 firmwareDec 4, 2023

  • CVE-2023-2044
    24Monitor

    Control iD iDSecure Dispositivos Page cross site scripting

    MediumCVSS 6.1No exploitEPSS 0%

    assaabloy · control id idsecureApr 14, 2023

  • There is a short key vulnerability in HID Global DigitalPersona (formerly Crossmatch) U.are.U 4500 Fingerprint Reader v24.

    MediumCVSS 5.9No exploitEPSS 1%

    assaabloy · hid digitalpersona 4500 firmwareJul 15, 2019

  • CVE-2026-3315
    23Monitor

    Local Privilege Escalation Due to Writable Executable in Privileged Visionline Service Path

    MediumCVSS 5.8No exploitEPSS 0%

    assaabloy · visionlineMar 10, 2026

  • CVE-2023-4392
    21Monitor

    Control iD Gerencia Web Cookie cleartext storage

    MediumCVSS 5.3No exploitEPSS 1%

    assaabloy · control id gerencia webAug 16, 2023

  • CVE-2025-2125
    21Monitor

    Control iD RH iD PDF Document companyId resource injection

    MediumCVSS 5.3No exploitEPSS 0%

    assaabloy · control id rhidMar 9, 2025