Filtered by vendor Bosch Subscriptions
Filtered by product Smart Home Subscriptions
Total 2 CVE
CVE Vendors Products Updated CVSS v3.1
CVE-2021-47708 2 Bosch, Commax 2 Smart Home, Smart Home System 2026-07-15 N/A
COMMAX Smart Home System CDP-1020n contains an SQL injection vulnerability that allows attackers to bypass authentication by injecting arbitrary SQL code through the 'id' parameter in 'loginstart.asp'. Attackers can exploit this by sending a POST request with malicious 'id' values to manipulate database queries and gain unauthorized access.
CVE-2020-6781 1 Bosch 1 Smart Home 2024-11-21 6.8 Medium
Improper certificate validation for certain connections in the Bosch Smart Home System App for iOS prior to version 9.17.1 potentially allows to intercept video contents by performing a man-in-the-middle attack.