CVE-2019-12804
In Hunesion i-oneNet version 3.0.7 ~ 3.0.53 and 4.0.4 ~ 4.0.16, due to the lack of update file integrity checking in the upgrade process, an attacker can craft malicious file and use it as an update.
Scoring
- Severity
- HIGH
- CVSS base score
- 7.8
- CVSS vector
- CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
- EPSS probability
- 0.10%
- CWE
- CWE-353
- Published
- 2019-07-10
- Last modified
- 2026-03-14
Affected products
- Hunesion i-oneNet
- Hunesion i-oneNet
Weakness type
Related vulnerabilities
- CVE-2021-26608 — handysoft groupware arbitrary file download and execution vulnerability
- CVE-2020-7810 — HandySoft ActiveX File Download and Execution Vulnerability
- CVE-2020-10266 — RVD#1487: No integrity checks on UR+ platform artifacts when installed in the robot
- CVE-2020-7808 — RAONWIZ Inc K Upload, arguments modiffication via missing support for integrity check vulnerability
- CVE-2019-11480 — Ubuntu kernel snap build process could use unauthenticated sources
- CVE-2021-28545 — Acrobat Reader DC Missing Support for Integrity Check
- CVE-2023-32475 — Dell BIOS contains a missing support for integrity check vulnerability. An attacker with physical access to the system c
- CVE-2025-48500 — BIG-IP APM VPN web client for macOS vulnerability