GogogateCVEs & Vulnerabilities

11 CVEs affecting Gogogate products, tracked from the National Vulnerability Database, with CVSS/EPSS scores and exploitation status.

Most Affected Products

ismartgate pro 11ismartgate pro firmware 11
CVE-2020-13119HIGH

ismartgate PRO 1.5.9 is vulnerable to clickjacking.

24 Sep 2020
8.1
CVSS
CVE-2020-12843CRITICAL

ismartgate PRO 1.5.9 is vulnerable to malicious file uploads via the form for uploading sounds to garage doors. The magic bytes for WAV must be used.

24 Sep 2020
9.8
CVSS
CVE-2020-12842CRITICAL

ismartgate PRO 1.5.9 is vulnerable to privilege escalation by appending PHP code to /cron/checkUserExpirationDate.php.

24 Sep 2020
9.8
CVSS
CVE-2020-12841MEDIUM

ismartgate PRO 1.5.9 is vulnerable to CSRF that allows remote attackers to upload imae files via /index.php

24 Sep 2020
6.5
CVSS
CVE-2020-12840MEDIUM

ismartgate PRO 1.5.9 is vulnerable to CSRF that allows remote attackers to upload sound files via /index.php

24 Sep 2020
6.5
CVSS
CVE-2020-12839CRITICAL

ismartgate PRO 1.5.9 is vulnerable to privilege escalation by appending PHP code to /cron/checkExpirationDate.php.

24 Sep 2020
9.8
CVSS
CVE-2020-12838CRITICAL

ismartgate PRO 1.5.9 is vulnerable to privilege escalation by appending PHP code to /cron/mailAdmin.php.

24 Sep 2020
9.8
CVSS
CVE-2020-12837HIGH

ismartgate PRO 1.5.9 is vulnerable to malicious file uploads via the form for uploading images to garage doors. The magic bytes of PNG must be used.

24 Sep 2020
7.5
CVSS
CVE-2020-12282HIGH

iSmartgate PRO 1.5.9 is vulnerable to CSRF via the busca parameter in the form used for searching for users, accessible via /index.php. (This can be combined with reflected XSS.)

24 Sep 2020
8.8
CVSS
CVE-2020-12281MEDIUM

iSmartgate PRO 1.5.9 is vulnerable to CSRF that allows remote attackers to create a new user via /index.php.

24 Sep 2020
6.5
CVSS
CVE-2020-12280MEDIUM

iSmartgate PRO 1.5.9 is vulnerable to CSRF that allows remote attackers to open/close a specified garage door/gate via /isg/opendoor.php.

24 Sep 2020
6.5
CVSS
← PrevPage 1 / 1Next →
Gogogate CVEs & Vulnerabilities — 11 Tracked