CVE-2023-3050 is a critical flaw in TMT Lockcell firmware where cookies are relied on in a security decision without adequate validation and integrity checking. According to the published NVD and advisory data, this can lead to authentication bypass and privilege abuse in versions before 15.0. The issue is network-reachable, requires no privileges or user interaction, and is rated CVSS 9.8.
CVE-2023-3049 is a critical vulnerability in TMT Lockcell before version 15. Public records describe an unrestricted upload of a file with a dangerous type that can lead to command injection. NVD rates the issue 9.8/10, indicating network-reachable impact with no privileges or user interaction required.
CVE-2023-3047 is a critical SQL injection vulnerability affecting TMT Lockcell firmware before version 15. The issue was published on 2023-06-13 and is rated CVSS 9.8, reflecting a network-reachable flaw with no required privileges or user interaction. Defensive attention should focus on identifying affected Lockcell deployments and upgrading or otherwise removing exposure where firmware remains below the [truncated]