Winstonprivacy operates a focused product line centered on the Winston device and its firmware, which, despite modest volume, occupies a prominent position in the vulnerability landscape. The vendor's disclosures skew strongly toward critical-severity outcomes and recur through a durable set of access-control and command-execution weaknesses—including CSRF, improper access control, OS command injection, and privilege management flaws—that reflect the administrative and network-facing role of the device. Live exploitation activity, public-exploit availability, and current severity counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Winstonprivacy over time
Signals from CVEs in this vendor scope (8 CVEs).
8 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-16257CRITICAL Winston 1.5.4 devices are vulnerable to command injection via the API. | Oct 28, 2020 | 9.8 | 31 | NO | NO |
CVE-2020-16259CRITICAL Winston 1.5.4 devices have an SSH user account with access from bastion hosts. This is undocumented in device documents and is not announced to the user. | Oct 28, 2020 | 9.8 | 30 | NO | NO |
CVE-2020-16256HIGH The API on Winston 1.5.4 devices is vulnerable to CSRF. | Oct 28, 2020 | 8.8 | 27 | NO | NO |
CVE-2020-16258HIGH Winston 1.5.4 devices make use of a Monit service (not managed during the normal user process) which is configured with default credentials. | Oct 28, 2020 | 7.1 | 24 | NO | NO |
CVE-2020-16263CRITICAL Winston 1.5.4 devices have a CORS configuration that trusts arbitrary origins. This allows requests to be made and viewed by arbitrary origins. | Oct 28, 2020 | 9.1 | 22 | NO | NO |
CVE-2020-16262HIGH Winston 1.5.4 devices have a local www-data user that is overly permissioned, resulting in root privilege escalation. | Oct 28, 2020 | 7.8 | 20 | NO | NO |
CVE-2020-16260HIGH Winston 1.5.4 devices do not enforce authorization. This is exploitable from the intranet, and can be combined with other vulnerabilities for remote exploitation. | Oct 28, 2020 | 7.5 | 19 | NO | NO |
CVE-2020-16261MEDIUM Winston 1.5.4 devices allow a U-Boot interrupt, resulting in local root access. | Oct 28, 2020 | 6.8 | 18 | NO | NO |
Signals from CVEs in this vendor scope (8 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Winstonprivacy.
Media articles that mention a CVE ID that affects a product developed by Winstonprivacy — matched by CVE ID, not by vendor name.