📦 Streamax Crocus

by Streamax

🔍 What is Streamax Crocus?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2025-11914

MEDIUM CVSS 4.3 Oct 17, 2025

This CVE describes a path traversal vulnerability in Shenzhen Ruiming Technology's Streamax Crocus system version 1.3.40. Attackers can manipulate the FilePath parameter in the /DeviceFileReport.do?Ac...

CVE-2025-11913

MEDIUM CVSS 4.3 Oct 17, 2025

This CVE describes a path traversal vulnerability in Shenzhen Ruiming Technology's Streamax Crocus system version 1.3.40. Attackers can remotely exploit the Download function to access arbitrary files...

CVE-2025-11911

MEDIUM CVSS 6.3 Oct 17, 2025

This SQL injection vulnerability in Shenzhen Ruiming Technology's Streamax Crocus system allows attackers to manipulate database queries through the sortField parameter. Attackers can potentially read...

CVE-2025-11912

MEDIUM CVSS 6.3 Oct 17, 2025

This CVE describes a SQL injection vulnerability in Shenzhen Ruiming Technology's Streamax Crocus system version 1.3.40. Attackers can remotely exploit the 'orderField' parameter in the /DeviceState.d...

CVE-2025-11910

MEDIUM CVSS 6.3 Oct 17, 2025

This CVE describes a SQL injection vulnerability in Shenzhen Ruiming Technology's Streamax Crocus system version 1.3.40. Attackers can remotely exploit the 'orderField' parameter in the /MemoryState.d...

CVE-2025-11909

MEDIUM CVSS 6.3 Oct 17, 2025

This CVE describes a SQL injection vulnerability in Shenzhen Ruiming Technology's Streamax Crocus system version 1.3.40. Attackers can manipulate the 'orderField' parameter in the /RepairRecord.do?Act...

CVE-2025-11908

MEDIUM CVSS 6.3 Oct 17, 2025

This vulnerability allows remote attackers to upload arbitrary files to Shenzhen Ruiming Technology Streamax Crocus systems via the /FileDir.do?Action=Upload endpoint. Attackers can exploit this to up...