Omninova's vulnerability footprint centers on its VoBot voice-interaction and embedded-firmware product line, which serves conversational AI and IoT deployment contexts. The durable signal reflects the authentication and certificate-handling demands of voice-interface and firmware contexts, with observed weakness classes including improper certificate validation, hard-coded credentials, and insufficient disclosure detail. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Omninova over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-6825CRITICAL An issue was discovered on VOBOT CLOCK before 0.99.30 devices. An SSH server exists with a hardcoded vobot account that has root access. | Feb 9, 2018 | 9.8 | 31 | NO | NO |
CVE-2018-6827HIGH VOBOT CLOCK before 0.99.30 devices do not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information, an | Feb 9, 2018 | 8.1 | 24 | NO | NO |
CVE-2018-6826HIGH An issue was discovered on VOBOT CLOCK before 0.99.30 devices. Cleartext HTTP is used to download a breakout program, and therefore man-in-the-middle attackers can execute arbitrar | Feb 9, 2018 | 7.5 | 24 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Omninova.
Media articles that mention a CVE ID that affects a product developed by Omninova — matched by CVE ID, not by vendor name.