Ehang Io's vulnerability footprint centers on a narrowly scoped network-performance and monitoring product (NPS) with modestly represented disclosures in the landscape. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Ehang Io over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-40494CRITICAL NPS before v0.26.10 was discovered to contain an authentication bypass vulnerability via constantly generating and sending the Auth key and Timestamp parameters. | Oct 6, 2022 | 9.8 | 30 | NO | NO |
CVE-2019-15119MEDIUM lib/install/install.go in cnlh nps through 0.23.2 uses 0777 permissions for /usr/local/bin/nps and/or /usr/bin/nps, leading to a file overwrite by a local user. | Aug 16, 2019 | 5.5 | 19 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Ehang Io.
Media articles that mention a CVE ID that affects a product developed by Ehang Io — matched by CVE ID, not by vendor name.