Chcnav produces GNSS positioning and navigation products with a narrow product portfolio but significant operational deployment in critical positioning and timing infrastructure. Vulnerabilities affecting this vendor skew toward serious outcomes and cluster around authentication and credential management weaknesses—including hard-coded credentials, improper authentication logic, authentication bypass via alternate channels, and cleartext storage of sensitive data—that are characteristic of embedded systems where credential handling is often treated as secondary to core functionality. Defenders relying on this vendor's equipment should prioritize inventory and credential auditing; current severity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Chcnav over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-30623CRITICAL The server checks the user's cookie in a non-standard way, and a value is entered in the cookie value name of the status and its value is set to true to bypass the identification w | Jul 18, 2022 | 9.8 | 28 | NO | NO |
CVE-2022-30627HIGH This vulnerability affects all of the company's products that also include the FW versions: update_i90_cv2.021_b20210104, update_i50_v1.0.55_b20200509, update_x6_v2.1.2_b202001127, | Jul 18, 2022 | 7.5 | 24 | NO | NO |
CVE-2022-30624HIGH Browsing the admin.html page allows the user to reset the admin password. Also appears in the JS code for the password. | Jul 18, 2022 | 7.5 | 24 | NO | NO |
CVE-2022-30622HIGH Disclosure of information - the system allows you to view usernames and passwords without permissions, thus it will be possible to enter the system. Path access: http://api/sys_use | Jul 17, 2022 | 7.3 | 23 | NO | NO |
CVE-2022-30626HIGH Browsing the path: http://ip/wifi_ap_pata_get.cmd, will show in the name of the existing access point on the component, and a password in clear text. | Jul 18, 2022 | 7.5 | 19 | NO | NO |
CVE-2022-30625MEDIUM Directory listing is a web server function that displays the directory contents when there is no index file in a specific website directory. A directory listing provides an attacke | Jul 18, 2022 | 5.3 | 19 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Chcnav.
Media articles that mention a CVE ID that affects a product developed by Chcnav — matched by CVE ID, not by vendor name.