Skip to content
Noroxi

mersive records

7 published records for vendor mersive.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
0
With a fix record
0%
Median publish → KEV
No record has entered KEV

All records

7 records
  • Insufficient validation of user-supplied input for the Solstice Pod before 2.8.4 networking configuration enables authenticated attackers to

    HighCVSS 8.8Proof of conceptEPSS 17%

    mersive · solstice firmwareNov 27, 2019

  • Solstice-Pod up to 5.0.2 WEBRTC server mishandles the format-string specifiers %x; %p; %c and %s in the screen_key, display_name, browser_na

    HighCVSS 7.5No exploitEPSS 2%

    mersive · solstice pod firmwareNov 11, 2020

  • In Solstice Pod before 3.0.3, the firmware can easily be decompiled/disassembled.

    HighCVSS 7.5No exploitEPSS 1%

    mersive · solstice firmwareDec 23, 2020

  • In Solstice Pod before 3.3.0 (or Open4.3), the screen key can be enumerated using brute-force attacks via the /lookin/info Solstice Open Con

    HighCVSS 7.5No exploitEPSS 1%

    mersive · solstice pod firmwareDec 23, 2020

  • In Solstice Pod before 3.3.0 (or Open4.3), the Administrator password can be enumerated using brute-force attacks via the /Config/service/in

    HighCVSS 7.5No exploitEPSS 1%

    mersive · solstice pod firmwareDec 23, 2020

  • Solstice Pod API Session Key Extraction via API Endpoint

    MediumCVSS 6.9No exploitEPSS 0%

    mersive · solstice pod firmwareDec 4, 2025

  • In Solstice Pod before 3.0.3, the web services allow users to connect to them over unencrypted channels via the Browser Look-in feature.

    MediumCVSS 5.9No exploitEPSS 1%

    mersive · solstice pod firmwareDec 23, 2020