Kramerav develops a narrow product line of visual communication and collaboration appliances, including the Via Go2 and Via Connect2 platforms along with their associated firmware and management software, that serve meeting rooms and enterprise AV environments. Vulnerabilities affecting this vendor skew strongly toward critical-severity outcomes and frequently acquire public exploit code, concentrating around file-upload validation, code injection, SQL injection, privilege management, and authorization flaws that are characteristic of web-facing appliance interfaces. Defenders treating Kramerav products as internet-exposed or accessible from untrusted networks should prioritize patching and inventory; live exploitation status and severity counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Kramerav over time
Signals from CVEs in this vendor scope (8 CVEs).
8 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-35064CRITICAL KramerAV VIAWare, all tested versions, allow privilege escalation through misconfiguration of sudo. Sudoers permits running of multiple dangerous commands, including unzip, systemc | Jul 12, 2021 | 9.8 | 84 | NO | YES |
CVE-2021-36356CRITICAL KRAMER VIAware through August 2021 allows remote attackers to execute arbitrary code because ajaxPages/writeBrowseFilePathAjax.php accepts arbitrary executable pathnames (even thou | Aug 31, 2021 | 9.8 | 78 | NO | YES |
CVE-2019-17124CRITICAL Kramer VIAware 2.5.0719.1034 has Incorrect Access Control. | Oct 9, 2019 | 9.8 | 55 | NO | YES |
CVE-2023-33509CRITICAL KramerAV VIA GO² < 4.0.1.1326 is vulnerable to SQL Injection. | May 31, 2023 | 9.8 | 28 | NO | NO |
CVE-2023-33508CRITICAL KramerAV VIA GO² < 4.0.1.1326 is vulnerable to unauthenticated file upload resulting in Remote Code Execution (RCE). | May 31, 2023 | 9.8 | 28 | NO | NO |
CVE-2023-33468CRITICAL KramerAV VIA Connect (2) and VIA Go (2) devices with a version prior to 4.0.1.1326 exhibit a vulnerability that enables remote manipulation of the device. This vulnerability involv | Aug 9, 2023 | 9.1 | 27 | NO | NO |
CVE-2023-33469HIGH In instances where the screen is visible and remote mouse connection is enabled, KramerAV VIA Connect (2) and VIA Go (2) devices with a version prior to 4.0.1.1326 can be exploited | Aug 9, 2023 | 7.8 | 24 | NO | NO |
CVE-2023-33507HIGH KramerAV VIA GO² < 4.0.1.1326 is vulnerable to Unauthenticated arbitrary file read. | May 31, 2023 | 7.5 | 23 | NO | NO |
Signals from CVEs in this vendor scope (8 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Kramerav.
Media articles that mention a CVE ID that affects a product developed by Kramerav — matched by CVE ID, not by vendor name.