Conceptronic
Conceptronic's vulnerability footprint centers on a narrow range of wireless networking and IP camera products, including its C54APM access point and CipCamPTIWL camera line, which operate as embedded networked devices with web-based management interfaces. Its disclosures cluster around web application and input-handling weaknesses—improper input validation, cross-site scripting, and cross-site request forgery—that are endemic to browser-facing embedded management interfaces, and vulnerabilities from this vendor frequently acquire public exploit code. Live severity and exploitation activity are shown alongside this summary.
Trends Over Time
The number and severity of CVEs published that impact products developed by Conceptronic over time
Products(7 total)
Top CVEs
Signals from CVEs in this vendor scope (8 CVEs).
8 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-6407HIGH An issue was discovered on Conceptronic CIPCAMPTIWL V3 0.61.30.21 devices. An unauthenticated attacker can crash a device by sending a POST request with a huge body size to /hy-cgi | Jan 30, 2018 | 7.5 | 40 | NO | NO |
CVE-2013-7204MEDIUM Cross-site request forgery (CSRF) vulnerability in set_users.cgi in Conceptronic CIPCAMPTIWL Camera 1.0 with firmware 21.37.2.49 allows remote attackers to hijack the authenticatio | Jan 17, 2014 | 6.8 | 38 | NO | YES |
CVE-2018-6408HIGH An issue was discovered on Conceptronic CIPCAMPTIWL V3 0.61.30.21 devices. CSRF exists in hy-cgi/user.cgi, as demonstrated by changing an administrator password or adding a new adm | Jan 30, 2018 | 8.8 | 26 | NO | NO |
CVE-2004-2045MEDIUM The HTTP administration interface on Conceptronic CADSLR1 ADSL router running firmware 3.04n allows remote attackers to cause a denial of service (device reboot) via an HTTP reques | Dec 31, 2004 | 5.0 | 23 | NO | YES |
CVE-2014-1408HIGH The Conceptronic C54APM access point with runtime code 1.26 has a default password of admin for the admin account, which makes it easier for remote attackers to obtain access via a | Jan 10, 2014 | 7.8 | 20 | NO | NO |
CVE-2014-1405MEDIUM Multiple open redirect vulnerabilities on the Conceptronic C54APM access point with runtime code 1.26 allow remote attackers to redirect users to arbitrary web sites and conduct ph | Jan 10, 2014 | 5.8 | 16 | NO | NO |
CVE-2014-1407MEDIUM Multiple cross-site scripting (XSS) vulnerabilities on the Conceptronic C54APM access point with runtime code 1.26 allow remote attackers to inject arbitrary web script or HTML via | Jan 10, 2014 | 4.3 | 14 | NO | NO |
CVE-2014-1406MEDIUM CRLF injection vulnerability in goform/formWlSiteSurvey on the Conceptronic C54APM access point with runtime code 1.26 allows remote attackers to inject arbitrary HTTP headers and | Jan 10, 2014 | 4.3 | 14 | NO | NO |
CVE Severity & Scoring
Exploit Exposure
Signals from CVEs in this vendor scope (8 CVEs).
Social Chatter
An overview of all social media posts that mention a CVE ID that affects a product developed by Conceptronic.
Media Mentions
Media articles that mention a CVE ID that affects a product developed by Conceptronic — matched by CVE ID, not by vendor name.