Getvera develops a focused line of home-automation hubs and controllers (VeraEdge and VeraLite product lines) that serve as central intelligence points for smart-home networks, presenting a modest but prominent footprint in the connected-device landscape. Vulnerabilities affecting the vendor skew toward serious outcomes, with an elevated share reaching critical severity, and recur across authentication weaknesses, path-traversal flaws, cross-site scripting, command injection, and memory-buffer issues that reflect the parsing and access-control demands of embedded control software. Defenders should monitor this vendor's firmware releases closely given the privileged role these devices occupy in home networks; live severity and exploitation counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Getvera over time
Signals from CVEs in this vendor scope (14 CVEs).
14 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-13598CRITICAL LuaUPnP in Vera Edge Home Controller 1.7.4452 allows remote unauthenticated users to execute arbitrary OS commands via the code parameter to /port_3480/data_request because the "No | Jul 14, 2019 | 9.8 | 33 | NO | NO |
CVE-2017-9385CRITICAL An issue was discovered on Vera Veralite 1.7.481 devices. The device has an additional OpenWRT interface in addition to the standard web interface which allows the highest privileg | Jun 17, 2019 | 9.8 | 32 | NO | NO |
CVE-2017-9383CRITICAL An issue was discovered on Vera VeraEdge 1.7.19 and Veralite 1.7.481 devices. The device provides UPnP services that are available on port 3480 and can also be accessed via port 80 | Jun 17, 2019 | 9.9 | 31 | NO | NO |
CVE-2019-15498HIGH cgi-bin/cmh/webcam.sh in Vera Edge Home Controller 1.7.4452 allows remote unauthenticated users to execute arbitrary OS commands via --output argument injection in the username par | Aug 23, 2019 | 8.8 | 29 | NO | NO |
CVE-2017-9392HIGH An issue was discovered on Vera VeraEdge 1.7.19 and Veralite 1.7.481 devices. The device provides UPnP services that are available on port 3480 and can also be accessed via port 80 | Jun 17, 2019 | 8.8 | 29 | NO | NO |
CVE-2017-9391HIGH An issue was discovered on Vera VeraEdge 1.7.19 and Veralite 1.7.481 devices. The device provides UPnP services that are available on port 3480 and can also be accessed via port 80 | Jun 17, 2019 | 8.8 | 29 | NO | NO |
CVE-2017-9389HIGH An issue was discovered on Vera VeraEdge 1.7.19 and Veralite 1.7.481 devices. The device provides a web user interface that allows a user to manage the device. As a part of the fun | Jun 17, 2019 | 8.8 | 29 | NO | NO |
CVE-2017-9388HIGH An issue was discovered on Vera VeraEdge 1.7.19 and Veralite 1.7.481 devices. The device provides a web user interface that allows a user to manage the device. As a part of the fun | Jun 17, 2019 | 8.8 | 29 | NO | NO |
CVE-2017-9384HIGH An issue was discovered on Vera VeraEdge 1.7.19 and Veralite 1.7.481 devices. The device provides a web user interface that allows a user to manage the device. As a part of the fun | Jun 17, 2019 | 8.8 | 28 | NO | NO |
CVE-2017-9381HIGH An issue was discovered on Vera VeraEdge 1.7.19 and Veralite 1.7.481 devices. The device provides a user with the capability of installing or deleting apps on the device using the | Jun 17, 2019 | 8.8 | 27 | NO | NO |
Signals from CVEs in this vendor scope (14 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Getvera.
Media articles that mention a CVE ID that affects a product developed by Getvera — matched by CVE ID, not by vendor name.