Szuray manufactures a focused line of compact embedded video-encoding and network appliances, with the recurring products across its portfolio including models such as the UHAE265-1-Mini, UHCE264 series, and UHE264 variants. Its vulnerabilities skew strongly toward critical-severity outcomes and frequently acquire public exploit code, concentrating in hardcoded credentials, path-traversal flaws, missing authentication on critical functions, and related access-control weaknesses that are characteristic of networked embedded devices with legacy design patterns. Defenders should prioritize inventory and access restriction for these appliances; live severity and exploit-availability counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Szuray over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-24217CRITICAL An issue was discovered in the box application on HiSilicon based IPTV/H.264/H.265 video encoders. The file-upload endpoint does not enforce authentication. Attackers can send an u | Oct 6, 2020 | 9.8 | 63 | NO | YES |
CVE-2020-24214CRITICAL An issue was discovered in the box application on HiSilicon based IPTV/H.264/H.265 video encoders. Attackers can send a crafted unauthenticated RTSP request to cause a buffer overf | Oct 6, 2020 | 9.8 | 60 | NO | YES |
CVE-2020-24215CRITICAL An issue was discovered in the box application on HiSilicon based IPTV/H.264/H.265 video encoders. Attackers can use hard-coded credentials in HTTP requests to perform any administ | Oct 6, 2020 | 9.8 | 52 | NO | YES |
CVE-2020-24219HIGH An issue was discovered on URayTech IPTV/H.264/H.265 video encoders through 1.97. Attackers can send crafted unauthenticated HTTP requests to exploit path traversal and pattern-mat | Oct 6, 2020 | 7.5 | 40 | NO | YES |
CVE-2020-24218CRITICAL An issue was discovered on URayTech IPTV/H.264/H.265 video encoders through 1.97. Attackers can log in as root via the password that is hard-coded in the executable file. | Oct 6, 2020 | 9.8 | 31 | NO | NO |
CVE-2020-24216HIGH An issue was discovered in the box application on HiSilicon based IPTV/H.264/H.265 video encoders. When the administrator configures a secret URL for RTSP streaming, the stream is | Oct 6, 2020 | 7.5 | 25 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Szuray.
Media articles that mention a CVE ID that affects a product developed by Szuray — matched by CVE ID, not by vendor name.