Streamax maintains a narrowly scoped video-surveillance product line centered on the Crocus platform, which serves as a backend management and streaming system for security deployments. Its vulnerability profile recurs through application-layer input-handling and access-control weaknesses, including injection flaws, SQL injection, path traversal, improper access controls, and unrestricted file uploads that are characteristic of web-facing management interfaces. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Streamax over time
Signals from CVEs in this vendor scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-11912HIGH A flaw has been found in Shenzhen Ruiming Technology Streamax Crocus 1.3.40. Affected is the function Query of the file /DeviceState.do?Action=Query. This manipulation of the argum | Oct 17, 2025 | 8.8 | 28 | NO | NO |
CVE-2025-11911HIGH A vulnerability was detected in Shenzhen Ruiming Technology Streamax Crocus 1.3.40. This impacts the function Query of the file /DeviceFault.do?Action=Query. The manipulation of th | Oct 17, 2025 | 8.8 | 28 | NO | NO |
CVE-2025-11910HIGH A security vulnerability has been detected in Shenzhen Ruiming Technology Streamax Crocus 1.3.40. This affects the function Query of the file /MemoryState.do?Action=Query. The mani | Oct 17, 2025 | 8.8 | 28 | NO | NO |
CVE-2025-11909HIGH A weakness has been identified in Shenzhen Ruiming Technology Streamax Crocus 1.3.40. The impacted element is the function queryLast of the file /RepairRecord.do?Action=QueryLast. | Oct 17, 2025 | 8.8 | 28 | NO | NO |
CVE-2025-11908HIGH A security flaw has been discovered in Shenzhen Ruiming Technology Streamax Crocus 1.3.40. The affected element is the function uploadFile of the file /FileDir.do?Action=Upload. Pe | Oct 17, 2025 | 8.8 | 28 | NO | NO |
CVE-2025-11914HIGH A vulnerability was found in Shenzhen Ruiming Technology Streamax Crocus 1.3.40. Affected by this issue is the function Download of the file /DeviceFileReport.do?Action=Download. P | Oct 17, 2025 | 7.5 | 25 | NO | NO |
CVE-2025-11913MEDIUM A vulnerability has been found in Shenzhen Ruiming Technology Streamax Crocus 1.3.40. Affected by this vulnerability is the function Download of the file /Service.do?Action=Downloa | Oct 17, 2025 | 6.5 | 23 | NO | NO |
Signals from CVEs in this vendor scope (7 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Streamax.
Media articles that mention a CVE ID that affects a product developed by Streamax — matched by CVE ID, not by vendor name.