Microdigital's vulnerability footprint centers on a narrow range of network video recording and surveillance appliances, including the MDC-N2190V and MDC-N4090 series, which occupy a prominent niche in security infrastructure deployments. Vulnerabilities affecting these devices skew strongly toward critical-severity outcomes and recur across firmware and hardware through weakness classes including buffer-overflow conditions, path-traversal flaws, CSRF, improper authentication, and OS command injection—exposures typical of embedded appliances with limited input sanitization and access controls. Defenders should prioritize inventory and patching of these appliances, particularly internet-facing instances; live exploitation activity and severity counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Microdigital over time
Signals from CVEs in this vendor scope (12 CVEs).
12 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-14698CRITICAL An issue was discovered on MicroDigital N-series cameras with firmware through 6400.0.8.5. In a CGI program running under the HTTPD web server, a buffer overflow in the param param | Aug 6, 2019 | 9.8 | 32 | NO | NO |
CVE-2019-14709CRITICAL A cleartext password storage issue was discovered on MicroDigital N-series cameras with firmware through 6400.0.8.5. The file in question is /usr/local/ipsca/mipsca.db. If a camera | Aug 6, 2019 | 9.8 | 31 | NO | NO |
CVE-2019-14708CRITICAL An issue was discovered on MicroDigital N-series cameras with firmware through 6400.0.8.5. A buffer overflow in the action parameter leads to remote code execution in the context o | Aug 6, 2019 | 9.8 | 31 | NO | NO |
CVE-2019-14699CRITICAL An issue was discovered on MicroDigital N-series cameras with firmware through 6400.0.8.5. An attacker can exploit OS Command Injection in the filename parameter for remote code ex | Aug 6, 2019 | 9.8 | 30 | NO | NO |
CVE-2019-14704CRITICAL An SSRF issue was discovered in HTTPD on MicroDigital N-series cameras with firmware through 6400.0.8.5 via FTP commands following a newline character in the uploadfile field. | Aug 6, 2019 | 9.8 | 28 | NO | NO |
CVE-2019-14702CRITICAL An issue was discovered on MicroDigital N-series cameras with firmware through 6400.0.8.5. SQL injection vulnerabilities exist in 13 forms that are reachable through HTTPD. An atta | Aug 6, 2019 | 9.8 | 28 | NO | NO |
CVE-2019-14703HIGH A CSRF issue was discovered in webparam?user&action=set¶m=add in HTTPD on MicroDigital N-series cameras with firmware through 6400.0.8.5 to create an admin account. | Aug 6, 2019 | 8.8 | 26 | NO | NO |
CVE-2019-14707HIGH An issue was discovered on MicroDigital N-series cameras with firmware through 6400.0.8.5. The firmware update process is insecure, leading to remote code execution. The attacker c | Aug 6, 2019 | 7.2 | 24 | NO | NO |
CVE-2019-14701HIGH An issue was discovered on MicroDigital N-series cameras with firmware through 6400.0.8.5. An attacker can trigger read operations on an arbitrary file via Path Traversal in the TZ | Aug 6, 2019 | 7.5 | 24 | NO | NO |
CVE-2019-14706HIGH A denial of service issue in HTTPD was discovered on MicroDigital N-series cameras with firmware through 6400.0.8.5. An attacker without authorization can upload a file to upload.p | Aug 6, 2019 | 7.5 | 23 | NO | NO |
Signals from CVEs in this vendor scope (12 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Microdigital.
Media articles that mention a CVE ID that affects a product developed by Microdigital — matched by CVE ID, not by vendor name.