Jollytech maintains a narrowly scoped product line centered on Lobby Track, a specialized access-control or facility-management system, whose vulnerability profile reflects the configuration and information-handling demands of such applications. The recurring exposure centers on sensitive-information disclosure, initialization with insecure defaults, and incomplete security-relevant documentation, which are characteristic weaknesses in systems managing authentication or access credentials. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Jollytech over time
Signals from CVEs in this vendor scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-17485HIGH Lobby Track Desktop contains default administrative credentials. An attacker could exploit this vulnerability to gain full access to the application. | Mar 21, 2019 | 7.8 | 25 | NO | NO |
CVE-2018-17488HIGH Lobby Track Desktop could allow a local attacker to gain elevated privileges on the system, caused by an error in the printer dialog. By visiting the kiosk and accessing the print | Mar 21, 2019 | 7.8 | 24 | NO | NO |
CVE-2018-17487HIGH Lobby Track Desktop could allow a local attacker to gain elevated privileges on the system, caused by an error in the printer dialog. By visiting the kiosk and signing in as a visi | Mar 21, 2019 | 7.8 | 23 | NO | NO |
CVE-2018-17484HIGH Lobby Track Desktop could allow a local attacker to obtain sensitive information, caused by an error in Sample Database.mdb database while in kiosk mode. By using attack vectors ou | Mar 21, 2019 | 7.1 | 22 | NO | NO |
CVE-2018-17486MEDIUM Lobby Track Desktop could allow a local attacker to bypass security restrictions, caused by an error in the find visitor function while in kiosk mode. By visiting the kiosk and sel | Mar 21, 2019 | 5.5 | 19 | NO | NO |
CVE-2018-17483MEDIUM Lobby Track Desktop could allow a local attacker to obtain sensitive information, caused by an error in Reports while in kiosk mode. By visiting the kiosk and viewing the driver's | Mar 21, 2019 | 5.5 | 19 | NO | NO |
CVE-2018-17482MEDIUM Lobby Track Desktop could allow a local attacker to obtain sensitive information, caused by an error in Reports while in kiosk mode. By visiting the kiosk and clicking on reports, | Mar 21, 2019 | 5.5 | 19 | NO | NO |
Signals from CVEs in this vendor scope (7 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Jollytech.
Media articles that mention a CVE ID that affects a product developed by Jollytech — matched by CVE ID, not by vendor name.