Unifiedremote develops a remote-control and automation platform whose vulnerability profile centers on access-control and authentication mechanisms, including improper authorization, insufficient authentication for critical functions, and XML external entity handling. The observed weakness classes reflect the application's role as a bridge between clients and controllable systems, where authentication and input-validation gaps can expose downstream device control. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Unifiedremote over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-3229CRITICAL Because the web management interface for Unified Intents' Unified Remote solution does not itself require authentication, a remote, unauthenticated attacker can change or disable a | Feb 6, 2023 | 9.8 | 76 | NO | YES |
CVE-2023-52252CRITICAL Unified Remote 3.13.0 allows remote attackers to execute arbitrary Lua code because of a wildcarded Access-Control-Allow-Origin for the Remote upload endpoint. | Dec 30, 2023 | 9.8 | 27 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Unifiedremote.
Media articles that mention a CVE ID that affects a product developed by Unifiedremote — matched by CVE ID, not by vendor name.