← Back

Spinetix

spinetix

5 CVEs • 12 products

Products (12)

Click to collapse
Toggle
Dsos
dsos
Diva Firmware
diva_firmware
Hmp350
hmp350
Hmp300
hmp300
Diva
diva
Hmp400
hmp400
Hmp400w
hmp400w

CVEs (5)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Spinetix
1Fusion Digital Signage
Jun 17, 2026
Dec 10, 2025
6.9 MEDIUM· v4
5.3 MEDIUM· v3
N/A· v2
SpinetiX Fusion Digital Signage 3.4.8 contains a username enumeration vulnerability in its login script that allows attackers to identify valid user accounts. Attackers can send crafted login requests with different user...Show more
SpinetiX Fusion Digital Signage 3.4.8 contains a username enumeration vulnerability in its login script that allows attackers to identify valid user accounts. Attackers can send crafted login requests with different usernames to distinguish between existing and non-existing accounts by analyzing the server's error responses.Show less
1Spinetix
1Fusion Digital Signage
Jun 17, 2026
Dec 10, 2025
8.7 HIGH· v4
7.5 HIGH· v3
N/A· v2
SpinetiX Fusion Digital Signage 3.4.8 contains an unauthenticated information disclosure vulnerability in the database backup directory. Attackers can access the /content/files/backups/ endpoint to download sensitive bac...Show more
SpinetiX Fusion Digital Signage 3.4.8 contains an unauthenticated information disclosure vulnerability in the database backup directory. Attackers can access the /content/files/backups/ endpoint to download sensitive backup files containing user credentials and system information.Show less
1Spinetix
1Fusion Digital Signage
Jun 17, 2026
Dec 10, 2025
6.9 MEDIUM· v4
8.8 HIGH· v3
N/A· v2
SpinetiX Fusion Digital Signage 3.4.8 contains a cross-site request forgery vulnerability that allows attackers to create administrative user accounts without proper request validation. Attackers can craft a malicious we...Show more
SpinetiX Fusion Digital Signage 3.4.8 contains a cross-site request forgery vulnerability that allows attackers to create administrative user accounts without proper request validation. Attackers can craft a malicious web page that automatically submits a form to create a new admin user with full system privileges when a logged-in user visits the page.Show less
1Spinetix
1Fusion Digital Signage
Jun 17, 2026
Dec 10, 2025
8.8 HIGH· v4
8.1 HIGH· v3
N/A· v2
SpinetiX Fusion Digital Signage 3.4.8 and lower contains an authenticated path traversal vulnerability that allows attackers to manipulate file backup and deletion operations through unverified input parameters. Attacker...Show more
SpinetiX Fusion Digital Signage 3.4.8 and lower contains an authenticated path traversal vulnerability that allows attackers to manipulate file backup and deletion operations through unverified input parameters. Attackers can exploit path traversal techniques in index.php to write backup files to arbitrary locations and delete files by manipulating backup and file delete requests.Show less
1Spinetix
6Diva Firmware
DsosHmp300 Firmware+3 more
Jun 17, 2026
Mar 24, 2021
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
spxmanage on certain SpinetiX devices allows requests that access unintended resources because of SSRF and Path Traversal. This affects HMP350, HMP300, and DiVA through 4.5.2-1.0.36229; HMP400 and HMP400W through 4.5.2-1...Show more
spxmanage on certain SpinetiX devices allows requests that access unintended resources because of SSRF and Path Traversal. This affects HMP350, HMP300, and DiVA through 4.5.2-1.0.36229; HMP400 and HMP400W through 4.5.2-1.0.2-1eb2ffbd; and DSOS through 4.5.2-1.0.2-1eb2ffbd.Show less