← Back

3960hd Firmware

3960hd_firmware

Vendor: Cohuhd • 5 CVEs

CVEs (5)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Cohuhd
13960hd Firmware
May 13, 2026
Nov 22, 2017
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Client-side enforcement using JavaScript of server-side security options on the Cohu 3960HD allows an attacker to manipulate options sent to the camera and cause malfunction or code execution, as demonstrated by a client...Show more
Client-side enforcement using JavaScript of server-side security options on the Cohu 3960HD allows an attacker to manipulate options sent to the camera and cause malfunction or code execution, as demonstrated by a client-side "if (!passwordsAreEqual())" test.Show less
1Cohuhd
13960hd Firmware
May 13, 2026
Nov 22, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Information disclosure of .esp source code on the Cohu 3960 allows an attacker to view sensitive information such as application logic with a simple web browser.
1Cohuhd
13960hd Firmware
May 13, 2026
Nov 22, 2017
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
The webupgrade function on the Cohu 3960HD does not verify the firmware upgrade files or process, allowing an attacker to upload a specially crafted postinstall.sh file that will be executed with "root" privileges.
1Cohuhd
13960hd Firmware
May 13, 2026
Nov 22, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Missing authentication for the remote configuration port 1236/tcp on the Cohu 3960HD allows an attacker to change configuration parameters such as IP address and username/password via specially crafted XML SOAP packets.
1Cohuhd
13960hd Firmware
May 13, 2026
Nov 22, 2017
N/A· v4
6.5 MEDIUM· v3
5.0 MEDIUM· v2
Information disclosure through directory listing on the Cohu 3960HD allows an attacker to view and download source code, log files, and other sensitive device information via a specially crafted web request with an extra...Show more
Information disclosure through directory listing on the Cohu 3960HD allows an attacker to view and download source code, log files, and other sensitive device information via a specially crafted web request with an extra / character, such as a "GET // HTTP/1.1" request.Show less