Auo develops solar energy monitoring and data-recording systems including solar data recorders and surveillance platforms deployed in renewable energy installations. The recurring vulnerability profile centers on application-layer input handling and data protection, with observed weakness classes spanning cross-site scripting, SQL injection, insufficiently protected credentials, missing encryption of sensitive data, and unrestricted file uploads—typical of web-facing administrative interfaces with limited security hardening. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Auo over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-12719CRITICAL An issue was discovered in Picture_Manage_mvc.aspx in AUO SunVeillance Monitoring System before v1.1.9e. There is an incorrect access control vulnerability that can allow an unauth | Nov 12, 2019 | 9.8 | 29 | NO | NO |
CVE-2019-11367CRITICAL An issue was discovered in AUO Solar Data Recorder before 1.3.0. The web portal uses HTTP Basic Authentication and provides the account and password in the WWW-Authenticate attribu | Jun 3, 2019 | 9.8 | 29 | NO | NO |
CVE-2019-11368MEDIUM Stored XSS was discovered in AUO Solar Data Recorder before 1.3.0 via the protect/config.htm addr parameter. | Jun 3, 2019 | 5.4 | 28 | NO | YES |
CVE-2019-12720HIGH AUO SunVeillance Monitoring System before v1.1.9e is vulnerable to mvc_send_mail.aspx (MailAdd parameter) SQL Injection. An Attacker can carry a SQL Injection payload to the server | Nov 12, 2019 | 7.5 | 23 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Auo.
Media articles that mention a CVE ID that affects a product developed by Auo — matched by CVE ID, not by vendor name.