Abus manufactures a range of security and alarm products spanning wireless alarm systems and IP-based video intercom devices, creating a physical-security attack surface across premises and perimeter protection. Vulnerabilities affecting the vendor skew strongly toward critical-severity outcomes and frequently acquire public exploit tooling, concentrating in recurring weakness classes including cleartext transmission of sensitive information, improper authentication, OS command injection, insufficiently random value generation, and classic buffer overflows that reflect the firmware and embedded-system constraints of these devices. Defenders should prioritize inventory and patching of affected alarm and intercom product lines, as the combination of critical severity and exploit availability raises the risk profile significantly; live exploitation and severity counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Abus over time
Signals from CVEs in this vendor scope (14 CVEs).
14 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-26609HIGH ABUS TVIP 20000-21150 devices allows remote attackers to execute arbitrary code via shell metacharacters in the /cgi-bin/mft/wireless_mft ap field. | Feb 27, 2023 | 7.2 | 55 | NO | YES |
CVE-2018-17879CRITICAL An issue was discovered on certain ABUS TVIP cameras. The CGI scripts allow remote attackers to execute code via system() as root. There are several injection points in various scr | Oct 26, 2023 | 9.8 | 38 | NO | NO |
CVE-2018-17558CRITICAL Hardcoded manufacturer credentials and an OS command injection vulnerability in the /cgi-bin/mft/ directory on ABUS TVIP TVIP20050 LM.1.6.18, TVIP10051 LM.1.6.18, TVIP11050 MG.1.6. | Oct 26, 2023 | 9.8 | 31 | NO | NO |
CVE-2018-17878CRITICAL Buffer Overflow vulnerability in certain ABUS TVIP cameras allows attackers to gain control of the program via crafted string sent to sprintf() function. | Oct 26, 2023 | 9.8 | 27 | NO | NO |
CVE-2020-14157HIGH The wireless-communication feature of the ABUS Secvest FUBE50001 device does not encrypt sensitive data such as PIN codes or IDs of used proximity chip keys (RFID tokens). This mak | Jun 17, 2020 | 8.1 | 26 | NO | NO |
CVE-2018-16739HIGH An issue was discovered on certain ABUS TVIP devices. Due to a path traversal in /opt/cgi/admin/filewrite, an attacker can write to files, and thus execute code arbitrarily with ro | Oct 26, 2023 | 8.8 | 25 | NO | NO |
CVE-2019-14261HIGH An issue was discovered on ABUS Secvest FUAA50000 3.01.01 devices. Due to an insufficient implementation of jamming detection, an attacker is able to suppress correctly received RF | Sep 3, 2019 | 7.5 | 25 | NO | NO |
CVE-2020-28973HIGH The ABUS Secvest wireless alarm system FUAA50000 (v3.01.17) fails to properly authenticate some requests to its built-in HTTPS interface. Someone can use this vulnerability to obta | Apr 21, 2021 | 7.5 | 24 | NO | NO |
CVE-2019-9863CRITICAL Due to the use of an insecure algorithm for rolling codes in the ABUS Secvest wireless alarm system FUAA50000 3.01.01 and its remote controls FUBE50014 and FUBE50015, an attacker i | Mar 27, 2019 | 9.8 | 24 | NO | NO |
CVE-2020-14158CRITICAL The ABUS Secvest FUMO50110 hybrid module does not have any security mechanism that ensures confidentiality or integrity of RF packets that are exchanged with an alarm panel. This m | Jul 30, 2020 | 9.1 | 23 | NO | NO |
Signals from CVEs in this vendor scope (14 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Abus.
Media articles that mention a CVE ID that affects a product developed by Abus — matched by CVE ID, not by vendor name.