Zipato manufactures smart-home automation hubs, specifically the Zipabox platform and its associated firmware, where the observed vulnerability signal centers on information-disclosure and encryption-strength issues. These represent foundational security concerns for a connected device handling home automation configuration and potentially sensitive user data; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Zipato over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-15123CRITICAL Insecure configuration storage in Zipato Zipabox Smart Home Controller BOARD REV - 1 with System Version -118 allows remote attacker perform new attack vectors and take under contr | Aug 13, 2018 | 9.8 | 29 | NO | NO |
CVE-2018-15124CRITICAL Weak hashing algorithm in Zipato Zipabox Smart Home Controller BOARD REV - 1 with System Version -118 allows unauthenticated attacker extract clear text passwords and get root acce | Aug 13, 2018 | 9.8 | 28 | NO | NO |
CVE-2018-15125HIGH Sensitive Information Disclosure in Zipato Zipabox Smart Home Controller allows remote attacker get sensitive information that expands attack surface. | Aug 13, 2018 | 7.5 | 24 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Zipato.
Media articles that mention a CVE ID that affects a product developed by Zipato — matched by CVE ID, not by vendor name.