Mobotix manufactures a narrow line of IP network cameras and associated control software, devices that are typically deployed in fixed surveillance infrastructure across enterprises and facilities. Vulnerabilities affecting the vendor skew strongly toward critical-severity outcomes and frequently acquire public exploit code, driven by recurring weaknesses in credential handling, authentication mechanisms, and web-interface security including cleartext transmission, hard-coded credentials, and cross-site scripting issues that are endemic to embedded network appliances. Defenders should prioritize patching exposed camera systems and control centers and restrict network access to management interfaces; live severity and exploitation counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Mobotix over time
Signals from CVEs in this vendor scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2009-5154CRITICAL An issue was discovered on MOBOTIX S14 MX-V4.2.1.61 devices. There is a default password of meinsm for the admin account. | Feb 9, 2019 | 9.8 | 31 | NO | NO |
CVE-2022-30018HIGH Mobotix Control Center (MxCC) through 2.5.4.5 has Insufficiently Protected Credentials, Storing Passwords in a Recoverable Format via the MxCC.ini config file. The credential stora | May 19, 2022 | 8.8 | 28 | NO | NO |
CVE-2019-12502HIGH There is a lack of CSRF countermeasures on MOBOTIX S14 MX-V4.2.1.61 cameras, as demonstrated by adding an admin account via the /admin/access URI. | May 31, 2019 | 8.8 | 27 | NO | NO |
CVE-2019-7674CRITICAL An issue was discovered on MOBOTIX S14 MX-V4.2.1.61 devices. /admin/access accepts a request to set the "aaaaa" password, considered insecure for some use cases, from a user. | Feb 9, 2019 | 9.8 | 24 | NO | NO |
CVE-2019-7675HIGH An issue was discovered on MOBOTIX S14 MX-V4.2.1.61 devices. The default management application is delivered over cleartext HTTP with Basic Authentication, as demonstrated by the / | Feb 9, 2019 | 7.5 | 23 | NO | NO |
CVE-2006-2490MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in Mobotix IP Network Cameras M1 1.9.4.7 and M10 2.0.5.2, and other versions before 2.2.3.18 for M10/D10 and 3.0.3.31 for M22, a | May 19, 2006 | 4.3 | 22 | NO | YES |
CVE-2019-7673HIGH An issue was discovered on MOBOTIX S14 MX-V4.2.1.61 devices. Administrator Credentials are stored in the 13-character DES hash format. | Feb 9, 2019 | 7.5 | 19 | NO | NO |
Signals from CVEs in this vendor scope (7 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Mobotix.
Media articles that mention a CVE ID that affects a product developed by Mobotix — matched by CVE ID, not by vendor name.