guoxinled records
4 published records for vendor guoxinled.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor1
- CWE-203 Observable Discrepancy1
- CWE-640 Weak Password Recovery Mechanism for Forgotten Password1
- CWE-798 Use of Hard-coded Credentials1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
4 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
39Monitor | CVE-2024-38466No exploit | Shenzhen Guoxin Synthesis image system before 8.3.0 has a 123456Qw default password.guoxinled · synthesis image system · CWE-798 | Critical9.8 | — | 0.4% | Jun 16, 2024 |
39Monitor | CVE-2024-38468No exploit | Shenzhen Guoxin Synthesis image system before 8.3.0 allows unauthorized password resets via the resetPassword API.guoxinled · synthesis image system · CWE-640 | Critical9.8 | — | 0.4% | Jun 16, 2024 |
30Monitor | CVE-2024-38467No exploit | Shenzhen Guoxin Synthesis image system before 8.3.0 allows unauthorized user information retrieval via the queryUser API.guoxinled · synthesis image system · CWE-200 | High7.5 | — | 0.4% | Jun 16, 2024 |
21Monitor | CVE-2024-38465No exploit | Shenzhen Guoxin Synthesis image system before 8.3.0 allows username enumeration because of the response discrepancy of incorrect versus erroguoxinled · synthesis image system · CWE-203 | Medium5.3 | — | 0.3% | Jun 16, 2024 |
- CVE-2024-3846639Monitor
Shenzhen Guoxin Synthesis image system before 8.3.0 has a 123456Qw default password.
CriticalCVSS 9.8No exploitEPSS 0%guoxinled · synthesis image systemJun 16, 2024
- CVE-2024-3846839Monitor
Shenzhen Guoxin Synthesis image system before 8.3.0 allows unauthorized password resets via the resetPassword API.
CriticalCVSS 9.8No exploitEPSS 0%guoxinled · synthesis image systemJun 16, 2024
- CVE-2024-3846730Monitor
Shenzhen Guoxin Synthesis image system before 8.3.0 allows unauthorized user information retrieval via the queryUser API.
HighCVSS 7.5No exploitEPSS 0%guoxinled · synthesis image systemJun 16, 2024
- CVE-2024-3846521Monitor
Shenzhen Guoxin Synthesis image system before 8.3.0 allows username enumeration because of the response discrepancy of incorrect versus erro
MediumCVSS 5.3No exploitEPSS 0%guoxinled · synthesis image systemJun 16, 2024