Megafeis produces the BofeiDBD database product line, which handles authentication and access control for its users. The recurring vulnerability pattern centers on authentication and authorization weaknesses—missing authorization checks, weak password recovery mechanisms, and insufficient password-strength requirements—that reflect the core security-sensitive functions these products perform. Current severity, exploitation status, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Megafeis over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-45637CRITICAL An insecure password reset issue discovered in MEGAFEIS, BOFEI DBD+ Application for IOS & Android v1.4.4 service via insecure expiry mechanism. | Mar 21, 2023 | 9.8 | 30 | NO | NO |
CVE-2022-45636HIGH An issue discovered in MEGAFEIS, BOFEI DBD+ Application for IOS & Android v1.4.4 allows attacker to unlock model(s) without authorization via arbitrary API requests. | Mar 21, 2023 | 8.1 | 26 | NO | NO |
CVE-2022-45635HIGH An issue discovered in MEGAFEIS, BOFEI DBD+ Application for IOS & Android v1.4.4 allows attacker to gain access to sensitive account information via insecure password policy. | Mar 21, 2023 | 7.5 | 25 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Megafeis.
Media articles that mention a CVE ID that affects a product developed by Megafeis — matched by CVE ID, not by vendor name.