Enttec develops entertainment and lighting control hardware and firmware products, including the DataGate and Pixelator lines, whose vulnerability profile centers on authentication and access-control weaknesses including hard-coded credentials, missing authentication for critical functions, and improper privilege management. The exposure also reflects application-layer input handling issues such as cross-site scripting and insecure permission assignment on firmware and configuration resources. Current CVE counts, exploitation activity, and severity distribution are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Enttec over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-12776CRITICAL An issue was discovered on the ENTTEC Datagate MK2, Storm 24, Pixelator, and E-Streamer MK2 with firmware 70044_update_05032019-482. They include a hard-coded SSH backdoor for remo | Jun 7, 2019 | 9.8 | 29 | NO | NO |
CVE-2019-12775HIGH An issue was discovered on the ENTTEC Datagate MK2, Storm 24, Pixelator, and E-Streamer MK2 with firmware 70044_update_05032019-482. They allow high-privileged root access by www-d | Jun 7, 2019 | 8.8 | 27 | NO | NO |
CVE-2019-6542HIGH ENTTEC Datagate MK2, Storm 24, Pixelator all firmware versions prior to (70044,70050,70060)_update_05032019-482 allows an unauthenticated user to initiate a remote reboot, which ma | Mar 28, 2019 | 7.5 | 24 | NO | NO |
CVE-2019-12777HIGH An issue was discovered on the ENTTEC Datagate MK2, Storm 24, Pixelator, and E-Streamer MK2 with firmware 70044_update_05032019-482. They replace secure and protected directory per | Jun 7, 2019 | 7.8 | 23 | NO | NO |
CVE-2019-12774MEDIUM A number of stored XSS vulnerabilities have been identified in the web configuration feature in ENTTEC Datagate Mk2 70044_update_05032019-482 that could allow an unauthenticated th | Jun 7, 2019 | 6.1 | 21 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Enttec.
Media articles that mention a CVE ID that affects a product developed by Enttec — matched by CVE ID, not by vendor name.