Gncchome's vulnerability footprint centers on its GNCC C2 command-and-control platform and associated firmware, a narrowly scoped product line serving network management and control functions. The observed weakness classes consistently involve credential and information-handling defects—including cleartext transmission of sensitive data, hard-coded credentials, improper authentication, and exposure of secrets to unauthorized actors—that reflect common embedded-system and management-interface design shortcomings. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Gncchome over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-31800MEDIUM Authentication Bypass in GNCC's GC2 Indoor Security Camera 1080P allows an attacker with physical access to gain a privileged command shell via the UART Debugging Port. | Aug 15, 2024 | 6.8 | 22 | NO | NO |
CVE-2024-31798MEDIUM Identical Hardcoded Root Password for All Devices in GNCC's GC2 Indoor Security Camera 1080P allows an attacker with physical access to retrieve the root password for all similar d | Aug 15, 2024 | 6.8 | 20 | NO | NO |
CVE-2024-31799MEDIUM Information Disclosure in GNCC's GC2 Indoor Security Camera 1080P allows an attacker with physical access to read the WiFi passphrase via the UART Debugging Port. | Aug 15, 2024 | 4.6 | 16 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Gncchome.
Media articles that mention a CVE ID that affects a product developed by Gncchome — matched by CVE ID, not by vendor name.