ThroughTek records
6 published records for vendor throughtek.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-121 Stack-based Buffer Overflow1
- CWE-290 Authentication Bypass by Spoofing1
- CWE-319 Cleartext Transmission of Sensitive Information1
- CWE-345 Insufficient Verification of Data Authenticity1
- CWE-457 Use of Uninitialized Variable1
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')1
The weakness classes this vendor ships most often: where to look.
CWEAll records
6 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
36Monitor | CVE-2023-6321No exploit | Owlet Camera OS command injectionowletcare · cam firmware · CWE-78 | High8.8 | — | 2.7% | May 15, 2024 |
35Monitor | CVE-2023-6322No exploit | Stack-based buffer overflow in message parser functionalityroku · indoor camera se firmware · CWE-121 | High8.8 | — | 1.0% | May 15, 2024 |
35Monitor | CVE-2023-6324No exploit | ThroughTek Kalay SDK error in handling the PSK identitythroughtek · kalay platform · CWE-457 | High8.8 | — | 0.7% | May 15, 2024 |
34Monitor | CVE-2021-28372No exploit | ThroughTek's Kalay Platform 2.0 network allows an attacker to impersonate an arbitrary ThroughTek (TUTK) device given a valid 20-byte uniquethroughtek · kalay p2p software development kit · CWE-290 | High8.3 | — | 2.6% | Aug 17, 2021 |
30Monitor | CVE-2021-32934No exploit | ThroughTek P2P SDK - Cleartext Transmission of Sensitive Informationthroughtek · kalay p2p software development kit · CWE-319 | High7.5 | — | 0.6% | May 19, 2022 |
26Monitor | CVE-2023-6323No exploit | ThroughTek Kalay SDK insufficient verification of message authenticitythroughtek · kalay platform · CWE-345 | Medium6.5 | — | 0.3% | May 15, 2024 |
- CVE-2023-632136Monitor
Owlet Camera OS command injection
HighCVSS 8.8No exploitEPSS 3%owletcare · cam firmwareMay 15, 2024
- CVE-2023-632235Monitor
Stack-based buffer overflow in message parser functionality
HighCVSS 8.8No exploitEPSS 1%roku · indoor camera se firmwareMay 15, 2024
- CVE-2023-632435Monitor
ThroughTek Kalay SDK error in handling the PSK identity
HighCVSS 8.8No exploitEPSS 1%throughtek · kalay platformMay 15, 2024
- CVE-2021-2837234Monitor
ThroughTek's Kalay Platform 2.0 network allows an attacker to impersonate an arbitrary ThroughTek (TUTK) device given a valid 20-byte unique
HighCVSS 8.3No exploitEPSS 3%throughtek · kalay p2p software development kitAug 17, 2021
- CVE-2021-3293430Monitor
ThroughTek P2P SDK - Cleartext Transmission of Sensitive Information
HighCVSS 7.5No exploitEPSS 1%throughtek · kalay p2p software development kitMay 19, 2022
- CVE-2023-632326Monitor
ThroughTek Kalay SDK insufficient verification of message authenticity
MediumCVSS 6.5No exploitEPSS 0%throughtek · kalay platformMay 15, 2024