Junhetec develops enterprise resource planning and point-of-sale systems alongside omnidirectional communication platforms, with observed vulnerabilities centered on web-application input handling and path-traversal weaknesses characteristic of application-layer security. Treat this as a compact vendor profile; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Junhetec over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-30173MEDIUM Local File Inclusion vulnerability of the omni-directional communication system allows remote authenticated attacker inject absolute path into Url parameter and access arbitrary fi | May 7, 2021 | 6.5 | 21 | NO | NO |
CVE-2021-30172MEDIUM Special characters of picture preview page in the Quan-Fang-Wei-Tong-Xun system are not filtered in users’ input, which allow remote authenticated attackers can inject malicious Ja | May 7, 2021 | 5.4 | 19 | NO | NO |
CVE-2021-30171MEDIUM Special characters of ERP POS news page are not filtered in users’ input, which allow remote authenticated attackers can inject malicious JavaScript and carry out stored XSS (Store | May 7, 2021 | 5.4 | 19 | NO | NO |
CVE-2021-30170MEDIUM Special characters of ERP POS customer profile page are not filtered in users’ input, which allow remote authenticated attackers can inject malicious JavaScript and carry out store | May 7, 2021 | 5.4 | 19 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Junhetec.
Media articles that mention a CVE ID that affects a product developed by Junhetec — matched by CVE ID, not by vendor name.