Micodus develops a focused line of industrial video surveillance and recording products, notably the MV720 series, where vulnerabilities cluster around authentication and access-control weaknesses including hard-coded credentials, user-controlled authorization keys, and missing authentication barriers on critical functions, alongside input-handling issues such as cross-site scripting. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Micodus over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-2107CRITICAL The MiCODUS MV720 GPS tracker API server has an authentication mechanism that allows devices to use a hard-coded master password. This may allow an attacker to send SMS commands di | Jul 20, 2022 | 9.8 | 33 | NO | NO |
CVE-2022-2141CRITICAL SMS-based GPS commands can be executed by MiCODUS MV720 GPS tracker without authentication. | Jul 20, 2022 | 9.8 | 31 | NO | NO |
CVE-2022-33944MEDIUM The main MiCODUS MV720 GPS tracker web server has an authenticated insecure direct object references vulnerability on endpoint and POST parameter “Device ID,” which accepts arbitra | Jul 20, 2022 | 6.5 | 21 | NO | NO |
CVE-2022-34150MEDIUM The main MiCODUS MV720 GPS tracker web server has an authenticated insecure direct object reference vulnerability on endpoint and parameter device IDs, which accept arbitrary devic | Jul 20, 2022 | 5.4 | 19 | NO | NO |
CVE-2022-2199MEDIUM The main MiCODUS MV720 GPS tracker web server has a reflected cross-site scripting vulnerability that could allow an attacker to gain control by tricking a user into making a reque | Jul 20, 2022 | 6.1 | 17 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Micodus.
Media articles that mention a CVE ID that affects a product developed by Micodus — matched by CVE ID, not by vendor name.