Metrics
Affected Vendors & Products
Mon, 20 Oct 2025 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Shenzhen Ruiming Technology
Shenzhen Ruiming Technology streamax Crocus |
|
| Vendors & Products |
Shenzhen Ruiming Technology
Shenzhen Ruiming Technology streamax Crocus |
Fri, 17 Oct 2025 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 17 Oct 2025 19:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability was detected in Shenzhen Ruiming Technology Streamax Crocus 1.3.40. This impacts the function Query of the file /DeviceFault.do?Action=Query. The manipulation of the argument sortField results in sql injection. It is possible to launch the attack remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way. | |
| Title | Shenzhen Ruiming Technology Streamax Crocus DeviceFault.do Query sql injection | |
| Weaknesses | CWE-74 CWE-89 |
|
| References |
| |
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published: 2025-10-17T19:32:07.988Z
Updated: 2025-10-17T19:52:31.061Z
Reserved: 2025-10-17T13:01:56.634Z
Link: CVE-2025-11911
Updated: 2025-10-17T19:52:04.741Z
Status : Awaiting Analysis
Published: 2025-10-17T20:15:37.060
Modified: 2025-10-21T19:31:50.020
Link: CVE-2025-11911
No data.