Computrols develops building-automation software and systems that manage facility controls and environmental systems, a niche but critical infrastructure domain. Its vulnerability profile centers on web-application and authentication weaknesses—hard-coded credentials, cross-site scripting, command injection, SQL injection, and cross-site request forgery—that recur across its control platforms and frequently acquire public exploit code. Defenders should treat this vendor's disclosures as high-priority for any exposed or internet-facing building-automation infrastructure; live severity and exploitation counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Computrols over time
Signals from CVEs in this vendor scope (10 CVEs).
10 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-10847HIGH Computrols CBAS 18.0.0 allows Cross-Site Request Forgery. | May 24, 2019 | 8.8 | 39 | NO | YES |
CVE-2019-10849HIGH Computrols CBAS 18.0.0 allows unprotected Subversion (SVN) directory / source code disclosure. | May 23, 2019 | 7.5 | 38 | NO | YES |
CVE-2019-10848MEDIUM Computrols CBAS 18.0.0 allows Username Enumeration. | May 24, 2019 | 5.3 | 32 | NO | YES |
CVE-2019-10846MEDIUM Computrols CBAS 18.0.0 allows Unauthenticated Reflected Cross-Site Scripting vulnerabilities in the login page and password reset page via the username GET parameter. | May 23, 2019 | 6.1 | 32 | NO | YES |
CVE-2019-10850CRITICAL Computrols CBAS 18.0.0 has Default Credentials. | May 23, 2019 | 9.8 | 30 | NO | NO |
CVE-2019-10854HIGH Computrols CBAS 18.0.0 allows Authenticated Command Injection. | May 23, 2019 | 8.8 | 29 | NO | NO |
CVE-2019-10852HIGH Computrols CBAS 18.0.0 allows Authenticated Blind SQL Injection via the id GET parameter, as demonstrated by the index.php?m=servers&a=start_pulling&id= substring. | May 23, 2019 | 8.8 | 27 | NO | NO |
CVE-2019-10853HIGH Computrols CBAS 18.0.0 allows Authentication Bypass. | May 23, 2019 | 8.1 | 26 | NO | NO |
CVE-2019-10855HIGH Computrols CBAS 18.0.0 mishandles password hashes. The approach is MD5 with a pw prefix, e.g., if the password is admin, it will calculate the MD5 hash of pwadmin and store it in a | May 23, 2019 | 7.5 | 24 | NO | NO |
CVE-2019-10851MEDIUM Computrols CBAS 18.0.0 has hard-coded encryption keys. | May 23, 2019 | 6.5 | 21 | NO | NO |
Signals from CVEs in this vendor scope (10 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Computrols.
Media articles that mention a CVE ID that affects a product developed by Computrols — matched by CVE ID, not by vendor name.