SercommCVEs & Vulnerabilities
2 CVEs affecting Sercomm products, tracked from the National Vulnerability Database, with CVSS/EPSS scores and exploitation status.
2 CVEs→ All vendors
Most Affected Products
agcombo vd625 firmware 1h500s 1h500s firmware 1agcombo vd625 1
CVE-2021-44080HIGH
A Command Injection vulnerability in httpd web server (setup.cgi) in SerComm h500s, FW: lowi-h500s-v3.4.22 allows logged in administrators to arbitrary OS commands as root in the device via the connection_type parameter of the statussupport_diagnostic_tracing.json endpoint.
2 Jun 2022
7.2
CVSS
CVE-2021-27132CRITICAL
SerComm AG Combo VD625 AGSOT_2.1.0 devices allow CRLF injection (for HTTP header injection) in the download function via the Content-Disposition header.
27 Feb 2021
9.8
CVSS
← PrevPage 1 / 1Next →