Kevinlab's vulnerability footprint concentrates in its 4ST L-BEMS building energy management system, with durable signals centered on application-layer input-handling weaknesses including path traversal, SQL injection, and related parsing issues. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Kevinlab over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-37291CRITICAL An SQL Injection vulnerability exists in KevinLAB Inc Building Energy Management System 4ST BEMS 1.0.0 ivia the input_id POST parameter in index.php. | Apr 11, 2022 | 9.8 | 48 | NO | YES |
CVE-2021-37292HIGH An Access Control vulnerability exists in KevinLAB Inc Building Energy Management System 4ST BEMS 1.0.0 due to an undocumented backdoor account. A malicious user can log in using t | Apr 11, 2022 | 7.2 | 40 | NO | YES |
CVE-2021-37293MEDIUM A Directory Traversal vulnerability exists in KevinLAB Inc Building Energy Management System 4ST BEMS 1.0.0 via the page GET parameter in index.php. | Apr 11, 2022 | 6.5 | 24 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Kevinlab.
Media articles that mention a CVE ID that affects a product developed by Kevinlab — matched by CVE ID, not by vendor name.