Keruigroup's vulnerability footprint centers on the YPC99 industrial control product and its associated firmware, with the recurring signal concentrated on application-level input-handling and authentication weaknesses including improper input validation and missing authentication for critical functions. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Keruigroup over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-13114CRITICAL Missing authentication and improper input validation in KERUI Wifi Endoscope Camera (YPC99) allow an attacker to execute arbitrary commands (with a length limit of 19 characters) v | Oct 22, 2018 | 9.8 | 30 | NO | NO |
CVE-2018-13115MEDIUM Lack of an authentication mechanism in KERUI Wifi Endoscope Camera (YPC99) allows an attacker to watch or block the camera stream. The RTSP server on port 7070 accepts the command | Oct 22, 2018 | 6.5 | 22 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Keruigroup.
Media articles that mention a CVE ID that affects a product developed by Keruigroup — matched by CVE ID, not by vendor name.