Apollotechnologiesinc operates a narrowly focused product line centered on the Momentum Axel 720P camera and its firmware, which presents an embedded-device attack surface. The durable signal in its vulnerability profile reflects authentication and access-control concerns, including improper certificate validation, credential protection weaknesses, and permission-assignment issues that are characteristic of networked hardware with legacy or simplified credential management. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Apollotechnologiesinc over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-12323MEDIUM An issue was discovered on Momentum Axel 720P 5.1.8 devices. A password of EHLGVG is hard-coded for the root and admin accounts, which makes it easier for physically proximate atta | Jun 13, 2018 | 6.8 | 21 | NO | NO |
CVE-2018-12260MEDIUM An issue was discovered on Momentum Axel 720P 5.1.8 devices. The root password can be obtained in cleartext by issuing the command 'showKey' from the root CLI. This password may be | Jun 12, 2018 | 6.7 | 20 | NO | NO |
CVE-2018-12259MEDIUM An issue was discovered on Momentum Axel 720P 5.1.8 devices. Root access can be obtained via UART pins without any restrictions, which leads to full system compromise. | Jun 12, 2018 | 6.8 | 20 | NO | NO |
CVE-2018-12258MEDIUM An issue was discovered on Momentum Axel 720P 5.1.8 devices. Custom Firmware Upgrade is possible via an SD Card. With physical access, an attacker can upgrade the firmware in under | Jun 12, 2018 | 6.8 | 20 | NO | NO |
CVE-2018-12261MEDIUM An issue was discovered on Momentum Axel 720P 5.1.8 devices. All processes run as root. | Jun 12, 2018 | 4.4 | 16 | NO | NO |
CVE-2018-12257MEDIUM An issue was discovered on Momentum Axel 720P 5.1.8 devices. There is Authenticated Custom Firmware Upgrade via DNS Hijacking. An authenticated root user with CLI access is able to | Jun 12, 2018 | 4.4 | 16 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Apollotechnologiesinc.
Media articles that mention a CVE ID that affects a product developed by Apollotechnologiesinc — matched by CVE ID, not by vendor name.