Stashcat is a niche vendor focused on the Heinekingmedia product line, a communication and collaboration platform whose vulnerability footprint centers on credential and authentication handling, with recurring issues including hard-coded credentials, missing authorization checks, and improper logging of sensitive information. Vulnerabilities affecting this vendor tend toward serious severity outcomes, reflecting the sensitivity of authentication and data-handling functions in communication infrastructure. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Stashcat over time
Signals from CVEs in this vendor scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2017-11130HIGH An issue was discovered in heinekingmedia StashCat through 1.7.5 for Android, through 0.0.80w for Web, and through 0.0.86 for Desktop. The product's protocol only tries to ensure c | Aug 1, 2017 | 8.1 | 24 | NO | NO |
CVE-2017-11129CRITICAL An issue was discovered in heinekingmedia StashCat through 1.7.5 for Android. The keystore is locked with a hard-coded password. Therefore, everyone with access to the keystore can | Aug 1, 2017 | 9.8 | 24 | NO | NO |
CVE-2017-11135HIGH An issue was discovered in heinekingmedia StashCat through 1.7.5 for Android, through 0.0.80w for Web, and through 0.0.86 for Desktop. The logout mechanism does not check for autho | Aug 1, 2017 | 7.5 | 21 | NO | NO |
CVE-2017-11131MEDIUM An issue was discovered in heinekingmedia StashCat through 1.7.5 for Android, through 0.0.80w for Web, and through 0.0.86 for Desktop. For authentication, the user password is hash | Aug 1, 2017 | 5.9 | 20 | NO | NO |
CVE-2017-11133HIGH An issue was discovered in heinekingmedia StashCat through 1.7.5 for Android, through 0.0.80w for Web, and through 0.0.86 for Desktop. To encrypt messages, AES in CBC mode is used | Aug 1, 2017 | 7.5 | 19 | NO | NO |
CVE-2017-11136MEDIUM An issue was discovered in heinekingmedia StashCat through 1.7.5 for Android, through 0.0.80w for Web, and through 0.0.86 for Desktop. It uses RSA to exchange a secret for symmetri | Aug 1, 2017 | 6.5 | 17 | NO | NO |
CVE-2017-11134MEDIUM An issue was discovered in heinekingmedia StashCat through 1.7.5 for Android. The login credentials are written into a log file on the device. Hence, an attacker with access to the | Aug 1, 2017 | 6.5 | 17 | NO | NO |
Signals from CVEs in this vendor scope (7 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Stashcat.
Media articles that mention a CVE ID that affects a product developed by Stashcat — matched by CVE ID, not by vendor name.