← Back

4st L Bems

4st_l-bems

Vendor: Kevinlab • 3 CVEs

CVEs (3)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Kevinlab
14st L Bems
Jul 5, 2026
Apr 11, 2022
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
A Directory Traversal vulnerability exists in KevinLAB Inc Building Energy Management System 4ST BEMS 1.0.0 via the page GET parameter in index.php.
1Kevinlab
14st L Bems
Jul 5, 2026
Apr 11, 2022
N/A· v4
7.2 HIGH· v3
9.0 HIGH· v2
An Access Control vulnerability exists in KevinLAB Inc Building Energy Management System 4ST BEMS 1.0.0 due to an undocumented backdoor account. A malicious user can log in using the backdor account with admin highest pr...Show more
An Access Control vulnerability exists in KevinLAB Inc Building Energy Management System 4ST BEMS 1.0.0 due to an undocumented backdoor account. A malicious user can log in using the backdor account with admin highest privileges and obtain system control.Show less
1Kevinlab
14st L Bems
Jul 5, 2026
Apr 11, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
An SQL Injection vulnerability exists in KevinLAB Inc Building Energy Management System 4ST BEMS 1.0.0 ivia the input_id POST parameter in index.php.