Govicture's vulnerability profile centers on a narrow portfolio of network appliances and firmware, including routers and managed switches such as the PC420, RX1800, and WR1200 series, which occupy edge and access-layer roles in smaller networks. Vulnerabilities affecting the vendor skew toward serious outcomes and cluster around authentication and access-control weakness classes—hard-coded credentials, missing authentication for critical functions, improper access control, OS command injection, and code injection—that are characteristic of embedded management interfaces with insufficient isolation from untrusted input. Defenders should audit these appliances for network exposure and prioritize firmware updates; live severity and exploitation counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Govicture over time
Signals from CVEs in this vendor scope (12 CVEs).
12 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-43283HIGH An issue was discovered on Victure WR1200 devices through 1.0.3. A command injection vulnerability was found within the web interface of the device, allowing an attacker with valid | Nov 30, 2021 | 8.8 | 30 | NO | NO |
CVE-2020-15744CRITICAL Stack-based Buffer Overflow vulnerability in the ONVIF server component of Victure PC420 smart camera allows an attacker to execute remote code on the target device. This issue aff | Aug 30, 2021 | 9.8 | 30 | NO | NO |
CVE-2019-15940CRITICAL Victure PC530 devices allow unauthenticated TELNET access as root. | Oct 1, 2019 | 9.8 | 30 | NO | NO |
CVE-2025-28200CRITICAL Victure RX1800 EN_V1.0.0_r12_110933 was discovered to utilize a weak default password which includes the last 8 digits of the Mac address. | May 9, 2025 | 9.8 | 27 | NO | NO |
CVE-2025-28203HIGH Victure RX1800 EN_V1.0.0_r12_110933 was discovered to contain a command injection vulnerability. | May 9, 2025 | 8.8 | 26 | NO | NO |
CVE-2023-41612HIGH Victure PC420 1.1.39 was discovered to use a weak encryption key for the file enabled_telnet.dat on the Micro SD card. | Sep 18, 2024 | 8.8 | 26 | NO | NO |
CVE-2021-43284HIGH An issue was discovered on Victure WR1200 devices through 1.0.3. The root SSH password never gets updated from its default value of admin. This enables an attacker to gain control | Nov 30, 2021 | 7.8 | 26 | NO | NO |
CVE-2025-28202HIGH Incorrect access control in Victure RX1800 EN_V1.0.0_r12_110933 allows attackers to enable SSH and Telnet services without authentication. | May 9, 2025 | 8.8 | 25 | NO | NO |
CVE-2023-41610HIGH Victure PC420 1.1.39 was discovered to contain a hardcoded root password which is stored in plaintext. | Sep 18, 2024 | 8.8 | 25 | NO | NO |
CVE-2021-43282MEDIUM An issue was discovered on Victure WR1200 devices through 1.0.3. The default Wi-Fi WPA2 key is advertised to anyone within Wi-Fi range through the router's MAC address. The device | Nov 30, 2021 | 6.5 | 23 | NO | NO |
Signals from CVEs in this vendor scope (12 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Govicture.
Media articles that mention a CVE ID that affects a product developed by Govicture — matched by CVE ID, not by vendor name.