Meritlilin produces a moderate portfolio of networking and storage devices including routers and appliances such as the P2G1022 and P2R series, with vulnerability disclosures clustering around credential exposure, sensitive information leakage, OS command injection, and missing authentication controls. These weakness classes reflect the embedded firmware and management interface attack surface typical of network infrastructure products; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Meritlilin over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-47618CRITICAL Merit LILIN AH55B04 & AH55B08 DVR firm has hard-coded administrator credentials. An unauthenticated remote attacker can use these credentials to log in administrator page, to manip | Jan 3, 2023 | 9.8 | 30 | NO | NO |
CVE-2021-30168CRITICAL The sensitive information of webcam device is not properly protected. Remote attackers can unauthentically grant administrator’s credential and further control the devices. | Apr 28, 2021 | 9.8 | 29 | NO | NO |
CVE-2021-30167CRITICAL The manage users profile services of the network camera device allows an authenticated. Remote attackers can modify URL parameters and further amend user’s information and escalate | Apr 28, 2021 | 9.8 | 29 | NO | NO |
CVE-2021-30166HIGH The NTP Server configuration function of the IP camera device is not verified with special parameters. Remote attackers can perform a command Injection attack and execute arbitrary | Apr 28, 2021 | 7.2 | 24 | NO | NO |
CVE-2021-30169HIGH The sensitive information of webcam device is not properly protected. Remote attackers can unauthentically grant user’s credential. | Apr 28, 2021 | 7.5 | 23 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Meritlilin.
Media articles that mention a CVE ID that affects a product developed by Meritlilin — matched by CVE ID, not by vendor name.