Stengg's vulnerability profile centers on the VPNCrypt M10 VPN appliance and its associated firmware, with observed weaknesses concentrated in OS command injection and missing authentication for critical functions. These are high-impact weakness classes typical of network appliances handling authentication and command execution; treat this as a compact vendor profile, with live severity, exploitation, and exposure counts shown alongside this summary.
The number and severity of CVEs published that impact products developed by Stengg over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-12107CRITICAL The Web portal of the WiFi module of VPNCrypt M10 2.6.5 allows command injection via a text field, which allow full control over this module's Operating System. | Aug 12, 2020 | 9.8 | 30 | NO | NO |
CVE-2020-12106CRITICAL The Web portal of the WiFi module of VPNCrypt M10 2.6.5 allows unauthenticated users to send HTTP POST request to several critical Administrative functions such as, changing creden | Aug 12, 2020 | 9.8 | 24 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Stengg.
Media articles that mention a CVE ID that affects a product developed by Stengg — matched by CVE ID, not by vendor name.