CVEs (3)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
4Owletcare RokuThroughtek+1 more5Cam 2 Firmware Cam FirmwareCam V3 Firmware+2 moreFeb 11, 2025 May 15, 2024 N/A· v4 8.8 HIGH· v3 N/A· v2 ThroughTek Kalay SDK uses a predictable PSK value in the DTLS session when encountering an unexpected PSK identity |
4Owletcare RokuThroughtek+1 more5Cam 2 Firmware Cam FirmwareCam V3 Firmware+2 moreFeb 11, 2025 May 15, 2024 N/A· v4 6.5 MEDIUM· v3 N/A· v2 ThroughTek Kalay SDK does not verify the authenticity of received messages, allowing an attacker to impersonate an authoritative server. |
2Owletcare Throughtek3Cam 2 Firmware Cam FirmwareKalay PlatformFeb 11, 2025 May 15, 2024 N/A· v4 8.8 HIGH· v3 N/A· v2 A command injection vulnerability exists in the IOCTL that manages OTA updates. A specially crafted command can lead to command execution as the root user. An attacker can make authenticated requests to trigger this vuln...Show more |