Aggregates CVE and security vulnerability intelligence across all meritlilin-related products, including CVSS, EPSS, publication dates, and vulnerability intelligence data.
Historical issues mainly involve vendor risk path handling and vendor risk command injection and related problems; some flaws may lead to vendor impact file overwrite, affecting vendor surface software deployment scenarios.
| CVE | Summary | Source | Max CVSS | EPSS % | Published | Updated |
|---|---|---|---|---|---|---|
| CVE-2022-47618 | Merit LILIN AH55B04 & AH55B08 DVR firm has hard-coded administrator credentials. An unauthenticated remote attacker can use these credentials to log in administrator page, to manipulate system or disrupt service. | [email protected] | 9.8 | 2.09% | 2023-01-03 | 2024-11-21 |
| CVE-2021-30169 | The sensitive information of webcam device is not properly protected. Remote attackers can unauthentically grant user’s credential. | [email protected] | 5.3 | 0.95% | 2021-04-28 | 2024-11-21 |
| CVE-2021-30168 | The sensitive information of webcam device is not properly protected. Remote attackers can unauthentically grant administrator’s credential and further control the devices. | [email protected] | 9.8 | 1.82% | 2021-04-28 | 2024-11-21 |
| CVE-2021-30167 | The manage users profile services of the network camera device allows an authenticated. Remote attackers can modify URL parameters and further amend user’s information and escalate privileges to control the devices. | [email protected] | 9.8 | 3.08% | 2021-04-28 | 2024-11-21 |
| CVE-2021-30166 | The NTP Server configuration function of the IP camera device is not verified with special parameters. Remote attackers can perform a command Injection attack and execute arbitrary commands after logging in with the privileged permission. | [email protected] | 7.2 | 6.58% | 2021-04-28 | 2024-11-21 |