Sfcyazilim develops SonLogger, a modestly represented logging and monitoring product with a vulnerability profile centered on authentication and file-handling weaknesses, specifically missing authentication controls on critical functions and unrestricted file uploads. These input-boundary and access-control issues are typical of web-facing administrative tools and reflect the exposure model of systems managing sensitive operational data. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Sfcyazilim over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-27964CRITICAL SonLogger before 6.4.1 is affected by Unauthenticated Arbitrary File Upload. An attacker can send a POST request to /Config/SaveUploadedHotspotLogoFile without any authentication o | Mar 5, 2021 | 9.8 | 75 | NO | YES |
CVE-2021-27963HIGH SonLogger before 6.4.1 is affected by user creation with any user permissions profile (e.g., SuperAdmin). An anonymous user can send a POST request to /User/saveUser without any au | Mar 5, 2021 | 8.2 | 25 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Sfcyazilim.
Media articles that mention a CVE ID that affects a product developed by Sfcyazilim — matched by CVE ID, not by vendor name.