IP
HD-analogique
Imagerie thermique
IP - 4G/5G
LCD/TFT
Autres
C-WERK
Caisson & Support
Clavier & Joystick
Objectif
PC Accessoires
Transmission
Please note that supplying your contact information with your report is entirely voluntary and at your discretion.
Participating in this vulnerability disclosure does not give you any right to intellectual property owned by Abetechs GmbH (Grundig Security) or a third party.
Abetechs GmbH (Grundig Security) publish vulnerability advisories on website, on the same page with Disclosure Policy.
ID
Date
Product
Description / Issue Summary
Affected Versions
Status / Fix
CWERK-2025-1
2024-07-10
C-Werk
Exposure of Licensing-Related Sensitive Information in Diagnostic Dumps
2.0.0 – 2.0.1
Fixed in v. 2.0.2
CWERK-2025-2
2024-10-12
Improper Session Cleanup on Role Removal in Web Admin Panel
before 2.0.3r
Fixed in v. 2.0.3
CWERK-2025-3
2025-01-19
Incorrect Evaluation of LDAP Nested Groups during Login
before 2.0.2
GU-IPC-1
2025-07-01
SmartLine IPS
A specific POST API request allows to change sensitive / embedded data like serial number and MAC address of the device. If certain values are changed, operation can no longer be guaranteed. Device can be bricked if non-ASSCI symbols are submitted.
V31.35.8.2.3.4 and timestamp 2310XX
FW V31.35.8.2.3.4 with timestamp 2401XX and above
GU-NVR-1
SmartLine NVR
A specific POST API request allows to change sensitive / embedded data like serial number and MAC addresses of the device. If certain values are changed, operation can no longer be guaranteed. Device can be bricked if non-ASSCI symbols are submitted.
FW V31.35.8.2.3.4 and timestamp 2310XX