Vulnerabilities
Vulnerable Software
Security Vulnerabilities
HCL iControl was affected by Missing Security Headers vulnerability. which lead to cross-site scripting (XSS) attacks by enabling the built-in XSS filtering mechanisms of modern web browsers.
CVSS Score
3.7
EPSS Score
0.001
Published
2026-06-04
The web administration panel binds broadly to the public IPv6 address space on port [::]:8080 without default firewall limits, making internal API endpoints reachable over the WAN.
CVSS Score
6.9
EPSS Score
0.0
Published
2026-06-04
The registration path /v1/account/register provides no bot mitigation mechanisms, allowing malicious automated systems to flood the database.
CVSS Score
8.8
EPSS Score
0.0
Published
2026-06-04
Fixed AES-128-CBC keys inside the AcerConnect OTA application let attackers forge authorization credentials for arbitrary IMEI numbers. This allows unauthorized actors to list catalog items and extract protected binaries from pre-signed cloud links.
CVSS Score
6.9
EPSS Score
0.0
Published
2026-06-04
The /v1/Plan service relies entirely on a shared global API token for full administrative management, allowing arbitrary creation of zero-cost network access plans.
CVSS Score
9.3
EPSS Score
0.0
Published
2026-06-04
The system Binder boundary accepts unverified pass-through AT commands, giving local applications the power to read baseband files or disable cellular connectivity.
CVSS Score
8.5
EPSS Score
0.0
Published
2026-06-04
High-risk TrustAllCerts routines disable standard TLS certificate validation. Combined with hard-coded DES symmetric encryption keys, a Man-in-the-Middle (MITM) actor could decrypt network traffic.
CVSS Score
9.2
EPSS Score
0.0
Published
2026-06-04
Broadcast events allow malicious software to rewrite the device's default Mobile Device Management (MDM) endpoint address, shifting administrative ownership to an external attacker.
CVSS Score
9.3
EPSS Score
0.0
Published
2026-06-04
The device encrypts data using AES-CBC with static zero-filled Initialization Vectors (IVs), making it susceptible to replay attacks and known-plaintext decryption.
CVSS Score
6.9
EPSS Score
0.0
Published
2026-06-04
Leftover engineering diagnostics and factory-level diagnostic software remain exposed on retail builds, giving malicious apps write privileges to internal NVRAM registers.
CVSS Score
8.8
EPSS Score
0.0
Published
2026-06-04


Contact Us

Shodan ® - All rights reserved