Dgtl develops HueMagic, a focused smart-home automation product for Philips Hue lighting systems, with the observable vulnerability signal centered on path-traversal weaknesses in its file-handling logic. Current severity, exploitation, and exposure metrics are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Dgtl over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-25864HIGH node-red-contrib-huemagic 3.0.0 is affected by hue/assets/..%2F Directory Traversal.in the res.sendFile API, used in file hue-magic.js, to fetch an arbitrary file. | Jan 26, 2021 | 7.5 | 37 | NO | YES |
CVE-2021-26504HIGH Directory Traversal vulnerability in Foddy node-red-contrib-huemagic version 3.0.0, allows remote attackers to gain sensitive information via crafted request in res.sendFile API in | Aug 11, 2023 | 7.5 | 21 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Dgtl.
Media articles that mention a CVE ID that affects a product developed by Dgtl — matched by CVE ID, not by vendor name.