CVE-2025-11914
- EPSS 0.12%
- Veröffentlicht 17.10.2025 20:32:05
- Zuletzt bearbeitet 31.10.2025 16:58:46
A vulnerability was found in Shenzhen Ruiming Technology Streamax Crocus 1.3.40. Affected by this issue is the function Download of the file /DeviceFileReport.do?Action=Download. Performing manipulation of the argument FilePath results in path traver...
CVE-2025-11913
- EPSS 0.12%
- Veröffentlicht 17.10.2025 20:02:08
- Zuletzt bearbeitet 31.10.2025 17:04:33
A vulnerability has been found in Shenzhen Ruiming Technology Streamax Crocus 1.3.40. Affected by this vulnerability is the function Download of the file /Service.do?Action=Download. Such manipulation of the argument Path leads to path traversal. The...
CVE-2025-11912
- EPSS 0.05%
- Veröffentlicht 17.10.2025 20:02:05
- Zuletzt bearbeitet 31.10.2025 17:09:07
A flaw has been found in Shenzhen Ruiming Technology Streamax Crocus 1.3.40. Affected is the function Query of the file /DeviceState.do?Action=Query. This manipulation of the argument orderField causes sql injection. The attack can be initiated remot...
CVE-2025-11911
- EPSS 0.05%
- Veröffentlicht 17.10.2025 19:32:07
- Zuletzt bearbeitet 31.10.2025 17:11:10
A vulnerability was detected in Shenzhen Ruiming Technology Streamax Crocus 1.3.40. This impacts the function Query of the file /DeviceFault.do?Action=Query. The manipulation of the argument sortField results in sql injection. It is possible to launc...
CVE-2025-11910
- EPSS 0.05%
- Veröffentlicht 17.10.2025 19:32:05
- Zuletzt bearbeitet 31.10.2025 17:12:36
A security vulnerability has been detected in Shenzhen Ruiming Technology Streamax Crocus 1.3.40. This affects the function Query of the file /MemoryState.do?Action=Query. The manipulation of the argument orderField leads to sql injection. It is poss...
CVE-2025-11909
- EPSS 0.05%
- Veröffentlicht 17.10.2025 18:32:07
- Zuletzt bearbeitet 31.10.2025 17:18:42
A weakness has been identified in Shenzhen Ruiming Technology Streamax Crocus 1.3.40. The impacted element is the function queryLast of the file /RepairRecord.do?Action=QueryLast. Executing manipulation of the argument orderField can lead to sql inje...
CVE-2025-11908
- EPSS 0.06%
- Veröffentlicht 17.10.2025 18:32:05
- Zuletzt bearbeitet 31.10.2025 17:19:39
A security flaw has been discovered in Shenzhen Ruiming Technology Streamax Crocus 1.3.40. The affected element is the function uploadFile of the file /FileDir.do?Action=Upload. Performing manipulation of the argument File results in unrestricted upl...