Vzug manufactures commercial kitchen appliances, particularly the Combi-Stream MSLQ combination steamer line, which integrates networked control and management interfaces. The recurring vulnerability classes—cleartext transmission of sensitive information, cross-site request forgery, insufficient authentication controls, and weak password hashing—reflect typical weaknesses in embedded appliance firmware and web-based management portals that lack security hardening. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Vzug over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-17215CRITICAL An issue was discovered on V-Zug Combi-Steam MSLQ devices before Ethernet R07 and before WLAN R05. There is no bruteforce protection (e.g., lockout) established. An attacker might | Oct 6, 2019 | 9.8 | 29 | NO | NO |
CVE-2019-17216CRITICAL An issue was discovered on V-Zug Combi-Steam MSLQ devices before Ethernet R07 and before WLAN R05. Password authentication uses MD5 to hash passwords. Cracking is possible with min | Oct 6, 2019 | 9.8 | 28 | NO | NO |
CVE-2019-17218CRITICAL An issue was discovered on V-Zug Combi-Steam MSLQ devices before Ethernet R07 and before WLAN R05. By default, the communication to the web service is unencrypted via http. An atta | Oct 6, 2019 | 9.1 | 27 | NO | NO |
CVE-2019-17219HIGH An issue was discovered on V-Zug Combi-Steam MSLQ devices before Ethernet R07 and before WLAN R05. By default, the device does not enforce any authentication. An adjacent attacker | Oct 6, 2019 | 8.8 | 26 | NO | NO |
CVE-2019-17217HIGH An issue was discovered on V-Zug Combi-Steam MSLQ devices before Ethernet R07 and before WLAN R05. There is no CSRF protection established on the web service. | Oct 6, 2019 | 8.8 | 26 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Vzug.
Media articles that mention a CVE ID that affects a product developed by Vzug — matched by CVE ID, not by vendor name.