Dbpower's vulnerability footprint centers on its U818A unmanned aerial vehicle and associated firmware, with the observed weakness classes clustering around access-control issues such as incorrect default permissions and missing authentication for critical functions. These characteristics are typical of consumer and light-commercial device firmware where secure-by-default configuration and authentication-gate enforcement are often secondary to initial time-to-market. Current exposure counts and severity figures are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Dbpower over time
Signals from CVEs in this vendor scope (1 CVEs).
1 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2017-3209HIGH The DBPOWER U818A WIFI quadcopter drone provides FTP access over its own local access point, and allows full file permissions to the anonymous user. The DBPower U818A WIFI quadcopt | Jul 24, 2018 | 8.1 | 25 | NO | NO |
Signals from CVEs in this vendor scope (1 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Dbpower.
Media articles that mention a CVE ID that affects a product developed by Dbpower — matched by CVE ID, not by vendor name.