Cohuhd's vulnerability footprint centers on its 3960HD surveillance camera and related firmware, with the recurring exposure rooted in authentication, file-upload, and information-disclosure weaknesses typical of networked device management interfaces. Treat this as a compact vendor profile; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Cohuhd over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2017-8864CRITICAL Client-side enforcement using JavaScript of server-side security options on the Cohu 3960HD allows an attacker to manipulate options sent to the camera and cause malfunction or cod | Nov 22, 2017 | 9.8 | 30 | NO | NO |
CVE-2017-8862CRITICAL The webupgrade function on the Cohu 3960HD does not verify the firmware upgrade files or process, allowing an attacker to upload a specially crafted postinstall.sh file that will b | Nov 22, 2017 | 9.8 | 30 | NO | NO |
CVE-2017-8861CRITICAL Missing authentication for the remote configuration port 1236/tcp on the Cohu 3960HD allows an attacker to change configuration parameters such as IP address and username/password | Nov 22, 2017 | 9.8 | 30 | NO | NO |
CVE-2017-8863HIGH Information disclosure of .esp source code on the Cohu 3960 allows an attacker to view sensitive information such as application logic with a simple web browser. | Nov 22, 2017 | 7.5 | 24 | NO | NO |
CVE-2017-8860MEDIUM Information disclosure through directory listing on the Cohu 3960HD allows an attacker to view and download source code, log files, and other sensitive device information via a spe | Nov 22, 2017 | 6.5 | 22 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Cohuhd.
Media articles that mention a CVE ID that affects a product developed by Cohuhd — matched by CVE ID, not by vendor name.