Hiby manufactures portable digital audio players and related firmware, with a focused product line centered on the R3 Pro series. Its disclosures to date have centered on file-handling weaknesses, particularly path-traversal and unrestricted file-upload vulnerabilities that expose the device's management interface and storage functionality; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Hiby over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-34496CRITICAL Hiby R3 PRO firmware v1.5 to v1.7 was discovered to contain a file upload vulnerability via the file upload feature. | Jul 29, 2022 | 9.8 | 30 | NO | NO |
CVE-2021-44124HIGH Hiby Music Hiby OS R3 Pro 1.5 and 1.6 is vulnerable to Directory Traversal. The HTTP Server does not have enough input data sanitization when shown data from SD Card, an attacker c | Mar 28, 2022 | 7.5 | 25 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Hiby.
Media articles that mention a CVE ID that affects a product developed by Hiby — matched by CVE ID, not by vendor name.