This page lists publicly disclosed CVE vulnerabilities affecting helmholz rex_100_firmware (linked via NVD CPE). Each row includes severity scores, summaries, and publication dates to help identify and analyze security issues.
| CVE | Summary | Source | Max CVSS | EPSS % | Published | Updated |
|---|---|---|---|---|---|---|
| CVE-2024-45276 | An unauthenticated remote attacker can get read access to files in the "/tmp" directory due to missing authentication. | [email protected] | 7.5 | 0.62% | 2024-10-15 | 2026-06-17 |
| CVE-2024-45275 | The devices contain two hard coded user accounts with hardcoded passwords that allow an unauthenticated remote attacker for full control of the affected devices. | [email protected] | 9.8 | 0.80% | 2024-10-15 | 2026-06-17 |
| CVE-2024-45274 | An unauthenticated remote attacker can execute OS commands via UDP on the device due to missing authentication. | [email protected] | 9.8 | 1.54% | 2024-10-15 | 2026-06-17 |
| CVE-2024-45273 | An unauthenticated local attacker can decrypt the devices config file and therefore compromise the device due to a weak implementation of the encryption used. | [email protected] | 8.4 | 0.07% | 2024-10-15 | 2026-06-17 |
| CVE-2024-45271 | An unauthenticated local attacker can gain admin privileges by deploying a config file due to improper input validation. | [email protected] | 8.4 | 0.31% | 2024-10-15 | 2026-06-17 |