Mobatime develops precision timekeeping and network synchronization appliances such as the AMXGT-100, along with associated web-based management applications that control and monitor these devices. The observed vulnerability pattern centers on authentication and authorization weaknesses—including improper credential validation, user-controlled authorization keys, and insecure storage of sensitive configuration data—reflecting the trust boundaries and access control demands of networked infrastructure management interfaces.
The number and severity of CVEs published that impact products developed by Mobatime over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-3033HIGH Incorrect Authorization vulnerability in Mobatime web application allows Privilege Escalation, Exploiting Incorrectly Configured Access Control Security Levels.This issue affects M | Jun 2, 2023 | 8.8 | 27 | NO | NO |
CVE-2023-3032HIGH Unrestricted Upload of File with Dangerous Type vulnerability in Mobatime web application (Documentary proof upload modules) allows a malicious user to Upload a Web Shell to a Web | Jun 2, 2023 | 8.8 | 27 | NO | NO |
CVE-2023-3066HIGH Incorrect Authorization vulnerability in Mobatime mobile application AMXGT100 allows a low-privileged user to impersonate anyone else, including administratorsThis issue affects Mo | Jun 5, 2023 | 8.1 | 25 | NO | NO |
CVE-2023-3065CRITICAL Improper Authentication vulnerability in Mobatime mobile application AMXGT100 allows Authentication Bypass.This issue affects Mobatime mobile application AMXGT100 through 1.3.20.
| Jun 5, 2023 | 9.1 | 22 | NO | NO |
CVE-2023-3064MEDIUM Anonymous user may get the list of existing users managed by the application, that could ease further attacks (see CVE-2023-3065 and 3066)This issue affects Mobatime mobile applica | Jun 5, 2023 | 5.3 | 15 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Mobatime.
Media articles that mention a CVE ID that affects a product developed by Mobatime — matched by CVE ID, not by vendor name.