Gogogate develops smart garage-door automation and control products, primarily its iSmartGate Pro line, which sit at the intersection of IoT devices and home-automation networks. Vulnerabilities affecting this vendor skew strongly toward critical-severity outcomes and recur through a consistent pattern of web-application and access-control weaknesses—cross-site request forgery, incorrect permission assignment, unrestricted file uploads, and UI-layer bypass issues—that reflect the challenges of securing embedded management interfaces exposed to both local and remote networks. Defenders deploying these devices should prioritize firmware updates and restrict management access; live severity and exploitation counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Gogogate over time
Signals from CVEs in this vendor scope (11 CVEs).
11 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-12838CRITICAL ismartgate PRO 1.5.9 is vulnerable to privilege escalation by appending PHP code to /cron/mailAdmin.php. | Sep 24, 2020 | 9.8 | 30 | NO | NO |
CVE-2020-12843CRITICAL ismartgate PRO 1.5.9 is vulnerable to malicious file uploads via the form for uploading sounds to garage doors. The magic bytes for WAV must be used. | Sep 24, 2020 | 9.8 | 24 | NO | NO |
CVE-2020-12842CRITICAL ismartgate PRO 1.5.9 is vulnerable to privilege escalation by appending PHP code to /cron/checkUserExpirationDate.php. | Sep 24, 2020 | 9.8 | 24 | NO | NO |
CVE-2020-12839CRITICAL ismartgate PRO 1.5.9 is vulnerable to privilege escalation by appending PHP code to /cron/checkExpirationDate.php. | Sep 24, 2020 | 9.8 | 24 | NO | NO |
CVE-2020-13119HIGH ismartgate PRO 1.5.9 is vulnerable to clickjacking. | Sep 24, 2020 | 8.1 | 23 | NO | NO |
CVE-2020-12282HIGH iSmartgate PRO 1.5.9 is vulnerable to CSRF via the busca parameter in the form used for searching for users, accessible via /index.php. (This can be combined with reflected XSS.) | Sep 24, 2020 | 8.8 | 22 | NO | NO |
CVE-2020-12840MEDIUM ismartgate PRO 1.5.9 is vulnerable to CSRF that allows remote attackers to upload sound files via /index.php | Sep 24, 2020 | 6.5 | 21 | NO | NO |
CVE-2020-12837HIGH ismartgate PRO 1.5.9 is vulnerable to malicious file uploads via the form for uploading images to garage doors. The magic bytes of PNG must be used. | Sep 24, 2020 | 7.5 | 19 | NO | NO |
CVE-2020-12841MEDIUM ismartgate PRO 1.5.9 is vulnerable to CSRF that allows remote attackers to upload imae files via /index.php | Sep 24, 2020 | 6.5 | 18 | NO | NO |
CVE-2020-12281MEDIUM iSmartgate PRO 1.5.9 is vulnerable to CSRF that allows remote attackers to create a new user via /index.php. | Sep 24, 2020 | 6.5 | 17 | NO | NO |
Signals from CVEs in this vendor scope (11 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Gogogate.
Media articles that mention a CVE ID that affects a product developed by Gogogate — matched by CVE ID, not by vendor name.