KylandCVEs & Vulnerabilities
2 CVEs affecting Kyland products, tracked from the National Vulnerability Database, with CVSS/EPSS scores and exploitation status.
2 CVEs→ All vendors
Most Affected Products
kps2204 6 port managed din-rail programmable serial device 2kps2204 6 port managed din-rail programmable serial device firmware 2
CVE-2020-25011CRITICAL
A sensitive information disclosure vulnerability in Kyland KPS2204 6 Port Managed Din-Rail Programmable Serial Device Servers Software Version:R0002.P05 allows remote attackers to get username and password by request /cgi-bin/webadminget.cgi script via the browser.
17 Dec 2020
9.8
CVSS
CVE-2020-25010CRITICAL
An arbitrary code execution vulnerability in Kyland KPS2204 6 Port Managed Din-Rail Programmable Serial Device Servers Software Version:R0002.P05 allows remote attackers to upload a malicious script file by constructing a POST type request and writing a payload in the request parameters as an instruction to write a file.
17 Dec 2020
9.8
CVSS
← PrevPage 1 / 1Next →