Company's vulnerability footprint centers on its CS-C2SHW hardware appliance and associated firmware, a narrowly scoped product line where disclosures cluster around memory-safety and cryptographic-validation issues such as out-of-bounds writes, OS command injection, and improper signature verification. Treat this as a compact vendor profile; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Company over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-27540CRITICAL Bash injection vulnerability and bypass of signature verification in Rostelecom CS-C2SHW 5.0.082.1. The camera reads firmware update configuration from SD card file vc\version.json | Jan 26, 2021 | 9.8 | 28 | NO | NO |
CVE-2020-27539CRITICAL Heap overflow with full parsing of HTTP respose in Rostelecom CS-C2SHW 5.0.082.1. AgentUpdater service has a self-written HTTP parser and builder. HTTP parser has a heap buffer ove | Jan 26, 2021 | 9.8 | 28 | NO | NO |
CVE-2020-27541HIGH Denial of Service vulnerability in Rostelecom CS-C2SHW 5.0.082.1. AgentGreen service has a bug in parsing broadcast discovery UDP packet. Sending a packet of too small size will le | Jan 26, 2021 | 7.5 | 23 | NO | NO |
CVE-2020-27542MEDIUM Rostelecom CS-C2SHW 5.0.082.1 is affected by: Bash command injection. The camera reads configuration from QR code (including network settings). The static IP configuration from QR | Jan 26, 2021 | 6.8 | 21 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Company.
Media articles that mention a CVE ID that affects a product developed by Company — matched by CVE ID, not by vendor name.