AI Score
Confidence
Low
EPSS
Percentile
28.0%
SSVC
Exploitation
none
Automatable
no
Technical Impact
total
Multiple Pimax products accept WebSocket connections from unintended endpoints. If this vulnerability is exploited, arbitrary code may be executed by a remote unauthenticated attacker.
[
{
"vendor": "Pimax",
"product": "Pimax Play",
"versions": [
{
"status": "affected",
"version": "prior to V1.21.01"
}
]
},
{
"vendor": "Pimax",
"product": "PiTool",
"versions": [
{
"status": "affected",
"version": "all versions"
}
]
}
]
[
{
"cpes": [
"cpe:2.3:a:pimax:pitool:*:*:*:*:*:*:*:*"
],
"vendor": "pimax",
"product": "pitool",
"versions": [
{
"status": "affected",
"version": "0",
"lessThan": "*",
"versionType": "custom"
}
],
"defaultStatus": "unknown"
},
{
"cpes": [
"cpe:2.3:a:pimax:play:*:*:*:*:*:*:*:*"
],
"vendor": "pimax",
"product": "play",
"versions": [
{
"status": "affected",
"version": "0",
"lessThan": "1.21.01",
"versionType": "custom"
}
],
"defaultStatus": "unknown"
}
]