abus records
14 published records for vendor abus.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 2
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-287 Improper Authentication2
- CWE-319 Cleartext Transmission of Sensitive Information2
- CWE-310 Cryptographic Issues2
- CWE-330 Use of Insufficiently Random Values1
- CWE-59 Improper Link Resolution Before File Access ('Link Following')1
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')1
The weakness classes this vendor ships most often: where to look.
CWEAll records
14 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
46Plan | CVE-2018-17879No exploit | An issue was discovered on certain ABUS TVIP cameras.abus · tvip 10000 firmware · CWE-78 | Critical9.8 | — | 21.9% | Oct 26, 2023 |
40Plan | CVE-2023-26609Proof of concept | ABUS TVIP 20000-21150 devices allows remote attackers to execute arbitrary code via shell metacharacters in the /cgi-bin/mft/wireless_mft apabus · tvip 20000-21150 firmware | High7.2 | — | 38.7% | Feb 26, 2023 |
40Plan | CVE-2018-17558No exploit | Hardcoded manufacturer credentials and an OS command injection vulnerability in the /cgi-bin/mft/ directory on ABUS TVIP TVIP20050 LM.1.6.18abus · tvip 10000 firmware · CWE-798 | Critical9.8 | — | 2.5% | Oct 26, 2023 |
40Plan | CVE-2019-9863No exploit | Due to the use of an insecure algorithm for rolling codes in the ABUS Secvest wireless alarm system FUAA50000 3.01.01 and its remote controlabus · secvest wireless alarm system fuaa50000 firmware · CWE-330 | Critical9.8 | — | 2.1% | Mar 27, 2019 |
39Monitor | CVE-2018-17878No exploit | Buffer Overflow vulnerability in certain ABUS TVIP cameras allows attackers to gain control of the program via crafted string sent to sprintabus · tvip 10000 firmware · CWE-120 | Critical9.8 | — | 0.8% | Oct 26, 2023 |
37Monitor | CVE-2020-14158No exploit | The ABUS Secvest FUMO50110 hybrid module does not have any security mechanism that ensures confidentiality or integrity of RF packets that aabus · secvest hybrid fumo50110 firmware · CWE-287 | Critical9.1 | — | 1.8% | Jul 30, 2020 |
35Monitor | CVE-2018-16739No exploit | An issue was discovered on certain ABUS TVIP devices.abus · tvip 10000 firmware · CWE-22 | High8.8 | — | 1.0% | Oct 26, 2023 |
32Monitor | CVE-2019-9861No exploit | Due to the use of an insecure RFID technology (MIFARE Classic), ABUS proximity chip keys (RFID tokens) of the ABUS Secvest FUAA50000 wirelesabus · secvest wireless alarm system fuaa50000 firmware · CWE-310 | High8.1 | — | 1.6% | May 14, 2019 |
32Monitor | CVE-2020-14157No exploit | The wireless-communication feature of the ABUS Secvest FUBE50001 device does not encrypt sensitive data such as PIN codes or IDs of used proabus · secvest wireless control fube50001 firmware · CWE-319 | High8.1 | — | 0.8% | Jun 17, 2020 |
31Monitor | CVE-2019-14261No exploit | An issue was discovered on ABUS Secvest FUAA50000 3.01.01 devices.abus · secvest wireless alarm system fuaa50000 firmware · CWE-310 | High7.5 | — | 2.5% | Sep 3, 2019 |
30Monitor | CVE-2020-28973No exploit | The ABUS Secvest wireless alarm system FUAA50000 (v3.01.17) fails to properly authenticate some requests to its built-in HTTPS interface.abus · secvest wireless alarm system fuaa50000 firmware · CWE-287 | High7.5 | — | 1.0% | Apr 21, 2021 |
30Monitor | CVE-2018-17559No exploit | Due to incorrect access control, unauthenticated remote attackers can view the /video.mjpg video stream of certain ABUS TVIP cameras.abus · tvip 10000 firmware · CWE-59 | High7.5 | — | 0.9% | Oct 26, 2023 |
30Monitor | CVE-2019-9860No exploit | Due to unencrypted signal communication and predictability of rolling codes, an attacker can "desynchronize" an ABUS Secvest wireless remoteabus · secvest wireless alarm system fuaa50000 firmware · CWE-319 | High7.5 | — | 0.8% | Mar 27, 2019 |
26Monitor | CVE-2019-9862No exploit | An issue was discovered on ABUS Secvest wireless alarm system FUAA50000 3.01.01 in conjunction with Secvest remote control FUBE50014 or FUBEabus · secvest wireless alarm system fuaa50000 firmware · CWE-311 | Medium6.5 | — | 0.6% | Mar 27, 2019 |
- CVE-2018-1787946Plan
An issue was discovered on certain ABUS TVIP cameras.
CriticalCVSS 9.8No exploitEPSS 22%abus · tvip 10000 firmwareOct 26, 2023
- CVE-2023-2660940Plan
ABUS TVIP 20000-21150 devices allows remote attackers to execute arbitrary code via shell metacharacters in the /cgi-bin/mft/wireless_mft ap
HighCVSS 7.2Proof of conceptEPSS 39%abus · tvip 20000-21150 firmwareFeb 26, 2023
- CVE-2018-1755840Plan
Hardcoded manufacturer credentials and an OS command injection vulnerability in the /cgi-bin/mft/ directory on ABUS TVIP TVIP20050 LM.1.6.18
CriticalCVSS 9.8No exploitEPSS 3%abus · tvip 10000 firmwareOct 26, 2023
- CVE-2019-986340Plan
Due to the use of an insecure algorithm for rolling codes in the ABUS Secvest wireless alarm system FUAA50000 3.01.01 and its remote control
CriticalCVSS 9.8No exploitEPSS 2%abus · secvest wireless alarm system fuaa50000 firmwareMar 27, 2019
- CVE-2018-1787839Monitor
Buffer Overflow vulnerability in certain ABUS TVIP cameras allows attackers to gain control of the program via crafted string sent to sprint
CriticalCVSS 9.8No exploitEPSS 1%abus · tvip 10000 firmwareOct 26, 2023
- CVE-2020-1415837Monitor
The ABUS Secvest FUMO50110 hybrid module does not have any security mechanism that ensures confidentiality or integrity of RF packets that a
CriticalCVSS 9.1No exploitEPSS 2%abus · secvest hybrid fumo50110 firmwareJul 30, 2020
- CVE-2018-1673935Monitor
An issue was discovered on certain ABUS TVIP devices.
HighCVSS 8.8No exploitEPSS 1%abus · tvip 10000 firmwareOct 26, 2023
- CVE-2019-986132Monitor
Due to the use of an insecure RFID technology (MIFARE Classic), ABUS proximity chip keys (RFID tokens) of the ABUS Secvest FUAA50000 wireles
HighCVSS 8.1No exploitEPSS 2%abus · secvest wireless alarm system fuaa50000 firmwareMay 14, 2019
- CVE-2020-1415732Monitor
The wireless-communication feature of the ABUS Secvest FUBE50001 device does not encrypt sensitive data such as PIN codes or IDs of used pro
HighCVSS 8.1No exploitEPSS 1%abus · secvest wireless control fube50001 firmwareJun 17, 2020
- CVE-2019-1426131Monitor
An issue was discovered on ABUS Secvest FUAA50000 3.01.01 devices.
HighCVSS 7.5No exploitEPSS 3%abus · secvest wireless alarm system fuaa50000 firmwareSep 3, 2019
- CVE-2020-2897330Monitor
The ABUS Secvest wireless alarm system FUAA50000 (v3.01.17) fails to properly authenticate some requests to its built-in HTTPS interface.
HighCVSS 7.5No exploitEPSS 1%abus · secvest wireless alarm system fuaa50000 firmwareApr 21, 2021
- CVE-2018-1755930Monitor
Due to incorrect access control, unauthenticated remote attackers can view the /video.mjpg video stream of certain ABUS TVIP cameras.
HighCVSS 7.5No exploitEPSS 1%abus · tvip 10000 firmwareOct 26, 2023
- CVE-2019-986030Monitor
Due to unencrypted signal communication and predictability of rolling codes, an attacker can "desynchronize" an ABUS Secvest wireless remote
HighCVSS 7.5No exploitEPSS 1%abus · secvest wireless alarm system fuaa50000 firmwareMar 27, 2019
- CVE-2019-986226Monitor
An issue was discovered on ABUS Secvest wireless alarm system FUAA50000 3.01.01 in conjunction with Secvest remote control FUBE50014 or FUBE
MediumCVSS 6.5No exploitEPSS 1%abus · secvest wireless alarm system fuaa50000 firmwareMar 27, 2019