Cpplusworld develops network video recorders and related firmware serving the surveillance and security appliance market, with a focused product portfolio centered on models such as the CP-VNR-3104 and CP-UVR-0401L1-4KH. The vulnerability profile across these devices reflects common embedded-systems and network-appliance weaknesses: improper certificate validation, insufficient input validation, exposure of sensitive information, and inadequately protected credentials, which are structural risks in internet-connected security equipment. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Cpplusworld over time
Signals from CVEs in this vendor scope (8 CVEs).
8 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-1518HIGH CP Plus KVMS Pro versions 2.01.0.T.190521 and prior are vulnerable to
sensitive credentials being leaked because they are insufficiently
protected.
| Mar 28, 2023 | 7.5 | 24 | NO | NO |
CVE-2023-3705HIGH The vulnerability exists in CP-Plus NVR due to an improper input handling at the web-based management interface of the affected product. An unauthenticated remote attacker could ex | Aug 24, 2023 | 7.5 | 22 | NO | NO |
CVE-2024-54848HIGH Improper handling and storage of certificates in CP Plus CP-VNR-3104 B3223P22C02424 allow attackers to decrypt communications or execute a man-in-the-middle attacks. | Jan 10, 2025 | 7.4 | 21 | NO | NO |
CVE-2024-54846MEDIUM An issue in CP Plus CP-VNR-3104 B3223P22C02424 allows attackers to obtain the EC private key and access sensitive data or execute a man-in-the-middle attack. | Jan 10, 2025 | 5.9 | 18 | NO | NO |
CVE-2024-54849MEDIUM An issue in CP Plus CP-VNR-3104 B3223P22C02424 allows attackers to obtain the second RSA private key and access sensitive data or execute a man-in-the-middle attack. | Jan 10, 2025 | 5.9 | 17 | NO | NO |
CVE-2024-54847MEDIUM An issue in CP Plus CP-VNR-3104 B3223P22C02424 allows attackers to access the Diffie-Hellman (DH) parameters and access sensitive data or execute a man-in-the-middle attack. | Jan 10, 2025 | 5.9 | 17 | NO | NO |
CVE-2023-3704MEDIUM The vulnerability exists in CP-Plus DVR due to an improper input validation within the web-based management interface of the affected products. An unauthenticated remote attacker c | Aug 24, 2023 | 5.3 | 17 | NO | NO |
CVE-2025-44039MEDIUM CP-XR-DE21-S -4G Router Firmware version 1.031.022 was discovered to contain insecure protections for its UART console. This vulnerability allows local attackers to connect to the | May 13, 2025 | 5.1 | 15 | NO | NO |
Signals from CVEs in this vendor scope (8 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Cpplusworld.
Media articles that mention a CVE ID that affects a product developed by Cpplusworld — matched by CVE ID, not by vendor name.