← Back

Gps Tracker

gps_tracker

Vendor: Uffizio • 5 CVEs

CVEs (5)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Uffizio
1Gps Tracker
Jun 17, 2026
Dec 16, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
A Remote Code Execution vulnerability exist in Uffizio's GPS Tracker all versions. The web server can be compromised by uploading and executing a web/reverse shell. An attacker could then run commands, browse system file...Show more
A Remote Code Execution vulnerability exist in Uffizio's GPS Tracker all versions. The web server can be compromised by uploading and executing a web/reverse shell. An attacker could then run commands, browse system files, and browse local resourcesShow less
1Uffizio
1Gps Tracker
Jun 17, 2026
Dec 16, 2023
N/A· v4
6.1 MEDIUM· v3
N/A· v2
An Open Redirection vulnerability exists in Uffizio's GPS Tracker all versions allows an attacker to construct a URL within the application that causes a redirection to an arbitrary external domain.
1Uffizio
1Gps Tracker
Jun 17, 2026
Dec 16, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
An improper access control vulnerability exists in Uffizio's GPS Tracker all versions that lead to sensitive information disclosure of all the connected devices. By visiting the vulnerable host at port 9000, we see it re...Show more
An improper access control vulnerability exists in Uffizio's GPS Tracker all versions that lead to sensitive information disclosure of all the connected devices. By visiting the vulnerable host at port 9000, we see it responds with a JSON body that has all the details about the devices which have been deployed.Show less
1Uffizio
1Gps Tracker
Jun 17, 2026
Apr 22, 2022
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
All versions of Uffizio GPS Tracker may allow an attacker to perform unintended actions on behalf of a user.
1Uffizio
1Gps Tracker
Jun 17, 2026
Apr 22, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
An attacker may be able to inject client-side JavaScript code on multiple instances within all versions of Uffizio GPS Tracker.