Unisoon's vulnerability footprint centers on its UltraLog Express logging and firmware products, with observed weaknesses concentrated in data-protection and access-control gaps such as cleartext storage of sensitive information, SQL injection, and missing authentication for critical functions. Treat this as a compact vendor profile; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Unisoon over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-3936CRITICAL UltraLog Express device management interface does not properly filter user inputted string in some specific parameters, attackers can inject arbitrary SQL command. | Mar 27, 2020 | 9.8 | 24 | NO | NO |
CVE-2020-3921HIGH UltraLog Express device management software stores user’s information in cleartext. Any user can obtain accounts information through a specific page. | Mar 27, 2020 | 7.5 | 24 | NO | NO |
CVE-2020-3920HIGH UltraLog Express device management interface does not properly perform access authentication in some specific pages/functions. Any user can access the privileged page to manage acc | Mar 27, 2020 | 8.1 | 20 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Unisoon.
Media articles that mention a CVE ID that affects a product developed by Unisoon — matched by CVE ID, not by vendor name.