Planex manufactures a modestly represented line of network and storage devices, including QR-series cameras and wireless media players, that typically operate in small-office and consumer environments. Vulnerabilities affecting the vendor skew toward serious outcomes, concentrating in web-interface and authentication weaknesses such as cross-site scripting, cross-site request forgery, hard-coded credentials, and debug-code exposure that are characteristic of embedded device firmware. Defenders should prioritize patching internet-exposed instances and review default credential usage across these product lines; live severity and exploitation counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Planex over time
Signals from CVEs in this vendor scope (14 CVEs).
14 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2017-12577CRITICAL An issue was discovered on the PLANEX CS-QR20 1.30. A hardcoded account / password ("admin:password") is used in the Android application that allows attackers to use a hidden API U | Aug 24, 2018 | 9.8 | 31 | NO | NO |
CVE-2017-12573HIGH An issue was discovered on PLANEX CS-W50HD devices with firmware before 030720. The device has a command-injection vulnerability in the web management UI on NAS settings page "/cgi | Aug 24, 2018 | 8.8 | 30 | NO | NO |
CVE-2013-6026HIGH The web interface on D-Link DIR-100, DIR-120, DI-624S, DI-524UP, DI-604S, DI-604UP, DI-604+, and TM-G5240 routers; Planex BRL-04R, BRL-04UR, and BRL-04CW routers; and Alpha Network | Oct 19, 2013 | 10.0 | 29 | NO | NO |
CVE-2023-22375HIGH Cross-site request forgery (CSRF) vulnerability in Wired/Wireless LAN Pan/Tilt Network Camera CS-WMV02G all versions allows a remote unauthenticated attacker to hijack the authenti | Feb 14, 2023 | 8.8 | 26 | NO | NO |
CVE-2017-12576HIGH An issue was discovered on the PLANEX CS-QR20 1.30. A hidden and undocumented management page allows an attacker to execute arbitrary code on the device when the user is authentica | Aug 24, 2018 | 7.2 | 25 | NO | NO |
CVE-2024-30220HIGH Command injection vulnerability in PLANEX COMMUNICATIONS wireless LAN routers allows a network-adjacent unauthenticated attacker to execute an arbitrary command by sending a specia | Apr 15, 2024 | 8.8 | 24 | NO | NO |
CVE-2022-38399MEDIUM Missing protection mechanism for alternate hardware interface in SmaCam CS-QR10 all versions and SmaCam Night Vision CS-QR20 all versions allows an attacker to execute an arbitrary | Sep 8, 2022 | 6.8 | 24 | NO | NO |
CVE-2021-37289HIGH Insecure Permissions in administration interface in Planex MZK-DP150N 1.42 and 1.43 allows attackers to execute system command as root via etc_ro/web/syscmd.asp. | Aug 22, 2022 | 7.2 | 24 | NO | NO |
CVE-2017-12574CRITICAL An issue was discovered on PLANEX CS-W50HD devices with firmware before 030720. A hardcoded credential "supervisor:dangerous" was injected into web authentication database "/.htpas | Aug 24, 2018 | 9.8 | 24 | NO | NO |
CVE-2024-45372MEDIUM MZK-DP300N firmware versions 1.04 and earlier contains a cross-site request forger vulnerability. Viewing a malicious page while logging in to the web management page of the affect | Sep 26, 2024 | 6.5 | 20 | NO | NO |
Signals from CVEs in this vendor scope (14 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Planex.
Media articles that mention a CVE ID that affects a product developed by Planex — matched by CVE ID, not by vendor name.