CVE-2019-25277
- EPSS 0.14%
- Veröffentlicht 07.01.2026 23:11:06
- Zuletzt bearbeitet 22.01.2026 13:47:52
FaceSentry Access Control System 6.4.8 contains a cross-site scripting vulnerability in the 'msg' parameter of pluginInstall.php that allows attackers to inject malicious scripts. Attackers can exploit the unvalidated input to execute arbitrary JavaS...
CVE-2019-25279
- EPSS 0.05%
- Veröffentlicht 07.01.2026 23:10:00
- Zuletzt bearbeitet 16.01.2026 19:16:06
FaceSentry Access Control System 6.4.8 contains a cleartext password storage vulnerability that allows attackers to access unencrypted credentials in the device's SQLite database. Attackers can directly read sensitive login information stored in /fac...
CVE-2019-25278
- EPSS 0.1%
- Veröffentlicht 07.01.2026 23:09:59
- Zuletzt bearbeitet 16.01.2026 19:16:05
FaceSentry Access Control System 6.4.8 contains a cleartext transmission vulnerability that allows remote attackers to intercept authentication credentials. Attackers can perform man-in-the-middle attacks to capture HTTP cookie authentication informa...
CVE-2019-25241
- EPSS 0.42%
- Veröffentlicht 24.12.2025 19:27:58
- Zuletzt bearbeitet 31.12.2025 14:15:50
FaceSentry Access Control System 6.4.8 contains a critical authentication vulnerability with hard-coded SSH credentials for the wwwuser account. Attackers can leverage the insecure sudoers configuration to escalate privileges and gain root access by ...
CVE-2019-25242
- EPSS 0.03%
- Veröffentlicht 24.12.2025 19:27:58
- Zuletzt bearbeitet 30.12.2025 20:14:33
FaceSentry Access Control System 6.4.8 contains a cross-site request forgery vulnerability that allows attackers to perform administrative actions without user consent. Attackers can craft malicious web pages to change administrator passwords, add ne...
CVE-2019-25243
- EPSS 1%
- Veröffentlicht 24.12.2025 19:27:58
- Zuletzt bearbeitet 30.12.2025 20:19:32
FaceSentry 6.4.8 contains an authenticated remote command injection vulnerability in pingTest.php and tcpPortTest.php scripts. Attackers can exploit unsanitized input parameters to inject and execute arbitrary shell commands with root privileges by m...
- EPSS 20.29%
- Veröffentlicht 04.05.2021 16:15:07
- Zuletzt bearbeitet 21.11.2024 05:12:59
iWT Ltd FaceSentry Access Control System 6.4.8 suffers from an authenticated OS command injection vulnerability using default credentials. This can be exploited to inject and execute arbitrary shell commands as the root user via the 'strInIP' POST pa...