Netop develops remote-control and monitoring software serving IT operations and support teams, a niche but high-value attack surface given the privileged access these tools command. Its vulnerability profile centers on its Vision Pro and Remote Control products and recurs through weakness classes including cleartext transmission of sensitive credentials, improper privilege and access controls, buffer boundary violations, and incorrect default permission settings—flaws that are particularly consequential in software handling authentication and system-level commands. Vulnerabilities affecting the vendor skew toward serious outcomes; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Netop over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-27193CRITICAL Incorrect default permissions vulnerability in the API of Netop Vision Pro up to and including 9.7.1 allows a remote unauthenticated attacker to read and write files on the remote | Mar 25, 2021 | 9.8 | 31 | NO | NO |
CVE-2021-27194HIGH Cleartext transmission of sensitive information in Netop Vision Pro up to and including 9.7.1 allows a remote unauthenticated attacker to gather credentials including Windows login | Mar 25, 2021 | 8.8 | 26 | NO | NO |
CVE-2021-27192HIGH Local privilege escalation vulnerability in Windows clients of Netop Vision Pro up to and including 9.7.1 allows a local user to gain administrator privileges whilst using the clie | Mar 25, 2021 | 7.8 | 24 | NO | NO |
CVE-2021-36134MEDIUM Out of bounds write vulnerability in the JPEG parsing code of Netop Vision Pro up to and including 9.7.2 allows an adjacent unauthenticated attacker to write to arbitrary memory po | Sep 27, 2021 | 6.5 | 23 | NO | NO |
CVE-2017-5216MEDIUM Stack-based buffer overflow vulnerability in Netop Remote Control versions 11.53, 12.21 and prior. The affected module in the Guest client is the "Import to Phonebook" option. When | Jan 9, 2017 | 5.5 | 21 | NO | NO |
CVE-2021-27195MEDIUM Improper Authorization vulnerability in Netop Vision Pro up to and including to 9.7.1 allows an attacker to replay network traffic. | Mar 25, 2021 | 5.9 | 20 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Netop.
Media articles that mention a CVE ID that affects a product developed by Netop — matched by CVE ID, not by vendor name.