Castel's vulnerability profile concentrates in its NextGen DVR product line, a class of digital video recording systems used in surveillance and security deployments, with recurrent weaknesses centered on authorization enforcement, cross-site request forgery protections, and credential storage. The durable signal reflects the web-interface and network-facing attack surface characteristic of remote-management features in embedded security appliances. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Castel over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-11679HIGH Castel NextGen DVR v1.0.0 is vulnerable to privilege escalation through the Adminstrator/Users/Edit/:UserId functionality. Adminstrator/Users/Edit/:UserId fails to check that the r | Jun 4, 2020 | 8.8 | 28 | NO | NO |
CVE-2020-11681HIGH Castel NextGen DVR v1.0.0 stores and displays credentials for the associated SMTP server in cleartext. Low privileged users can exploit this to create an administrator user and obt | Jun 4, 2020 | 8.1 | 25 | NO | NO |
CVE-2020-11682MEDIUM Castel NextGen DVR v1.0.0 is vulnerable to CSRF in all state-changing request. A __RequestVerificationToken is set by the web interface, and included in requests sent by web interf | Jun 4, 2020 | 6.5 | 17 | NO | NO |
CVE-2020-11680MEDIUM Castel NextGen DVR v1.0.0 is vulnerable to authorization bypass on all administrator functionality. The application fails to check that a request was submitted by an administrator. | Jun 4, 2020 | 6.5 | 17 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Castel.
Media articles that mention a CVE ID that affects a product developed by Castel — matched by CVE ID, not by vendor name.