Androvideo develops a narrowly scoped video player and firmware product line with a durable exposure pattern centered on authentication and information-disclosure weaknesses, including missing authentication for critical functions, sensitive data exposure, and improper credential validation. The vulnerability profile reflects typical weaknesses of web-accessible media applications and firmware, recurring across path-traversal and cross-site scripting vectors that affect input handling and access control. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Androvideo over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-13405CRITICAL A broken access control vulnerability found in Advan VD-1 firmware version 230 leads to insecure ADB service. An attacker can send a POST request to cgibin/AdbSetting.cgi to enable | Aug 29, 2019 | 9.8 | 30 | NO | NO |
CVE-2019-11064CRITICAL A vulnerability of remote credential disclosure was discovered in Advan VD-1 firmware versions up to 230. An attacker can export system configuration which is not encrypted to get | Aug 29, 2019 | 9.8 | 28 | NO | NO |
CVE-2019-13408HIGH A relative path traversal vulnerability found in Advan VD-1 firmware versions up to 230. It allows attackers to download arbitrary files via url cgibin/ExportSettings.cgi?Download= | Aug 29, 2019 | 7.5 | 23 | NO | NO |
CVE-2019-13406HIGH A broken access control vulnerability found in Advan VD-1 firmware versions up to 230. An attacker can send a POST request to cgibin/ApkUpload.cgi to install arbitrary APK without | Aug 29, 2019 | 7.5 | 23 | NO | NO |
CVE-2019-13407MEDIUM A XSS found in Advan VD-1 firmware versions up to 230. VD-1 responses a path error message when a requested resource was not found in page cgibin/ssi.cgi. It leads to a reflected X | Aug 29, 2019 | 6.1 | 20 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Androvideo.
Media articles that mention a CVE ID that affects a product developed by Androvideo — matched by CVE ID, not by vendor name.