Aver develops a focused line of presentation and conferencing hardware and control software, with identified vulnerabilities concentrating in its EH6108H encoder products and PTZApp control application. The durable signal centers on information-disclosure and access-control weaknesses, including exposure of sensitive data, path traversal, and hard-coded credentials that are characteristic of networked media and device-management interfaces. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Aver over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2016-6536CRITICAL The /setup URI on AVer Information EH6108H+ devices with firmware X9.03.24.00.07l allows remote attackers to bypass intended page-access restrictions or modify passwords by leverag | Sep 19, 2016 | 9.8 | 31 | NO | NO |
CVE-2016-6537HIGH AVer Information EH6108H+ devices with firmware X9.03.24.00.07l store passwords in a cleartext base64 format and require cleartext credentials in HTTP Cookie headers, which allows | Sep 19, 2016 | 7.5 | 25 | NO | NO |
CVE-2016-6535CRITICAL AVer Information EH6108H+ devices with firmware X9.03.24.00.07l have hardcoded accounts, which allows remote attackers to obtain root access by leveraging knowledge of the credenti | Sep 19, 2016 | 9.8 | 24 | NO | NO |
CVE-2023-27055HIGH Aver Information Inc PTZApp2 v20.01044.48 allows attackers to access sensitive files via a crafted GET request. | Mar 24, 2023 | 7.5 | 19 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Aver.
Media articles that mention a CVE ID that affects a product developed by Aver — matched by CVE ID, not by vendor name.