Keruistore produces a focused line of wireless home-security and alarm-system devices, including the K259 and W18 product families, where vulnerabilities cluster around authentication and command-injection flaws characteristic of IoT firmware. The recurring weakness classes—capture-replay authentication bypasses and improper command-neutralization issues—reflect the access-control and input-handling demands of remotely managed security devices. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Keruistore over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-63296MEDIUM KERUI K259 5MP Wi-Fi / Tuya Smart Security Camera firmware v33.53.87 contains a code execution vulnerability in its boot/update logic: during startup /usr/sbin/anyka_service.sh sca | Nov 10, 2025 | 6.5 | 22 | NO | NO |
CVE-2023-31759HIGH Weak Security in the 433MHz keyfob of Kerui W18 Alarm System v1.0 allows attackers to gain full access via a code replay attack. | May 24, 2023 | 7.5 | 22 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Keruistore.
Media articles that mention a CVE ID that affects a product developed by Keruistore — matched by CVE ID, not by vendor name.