Vulnerability registry

Consequence-scored vulnerabilities in cyber-physical systems and AI devices. Search by device, vendor, CVE, or path.

40 matching records

IDVulnerabilityDeviceSystem classPathScoreCVSS
CPATH-2026-0001Static engineering credentials exposed in a mobile application
Blood-pressure monitor and companion applicationQardioARM A100, Heart Health iOS 2.7.4
Qardio
Wearable healthAccount authorityCRITICALCVSS v3.1 6.6 MEDIUM
CPATH-2026-0002Insufficient audit logging
Portable ventilator systemLife2000 Ventilation System 06.08.00.00 and earlier, Life2000 Service PC
Baxter
Medical IoTObservability and recoveryMONITORCVSS v3.1 10 CRITICAL
CPATH-2026-0003Unsigned firmware loading and hard-coded network beacon
Patient monitorContec CMS8000
Contec
Medical IoTFirmware trust root · Device-control safety · Data privacyCRITICALCVSS v4.0 8.2 HIGH
CPATH-2026-0004Unprotected JTAG flash read/write access
Portable ventilatorLife2000 Ventilation System 06.08.00.00 and earlier
Baxter
Medical IoTDevice-control safety · Firmware trust rootCRITICALCVSS v3.1 9.3 CRITICAL
CPATH-2026-0005Hard-coded clinician credentials
Portable ventilatorLife2000 Ventilation System 06.08.00.00 and earlier
Baxter
Medical IoTAccount authorityCRITICALCVSS v3.1 9.3 CRITICAL
CPATH-2026-0006UDP out-of-bounds write
Patient monitorContec CMS8000
Contec
Medical IoTDevice-control safety · Device availability and recoveryEMERGENCYCVSS v3.1 9.8 CRITICAL
CPATH-2026-0007Unauthenticated BLE measurement-flood denial of service
Blood-pressure monitor and companion applicationsQardioARM A100, Heart Health iOS 2.7.4, Heart Health Android 2.5.1
Qardio
Wearable healthDevice availability and recoveryELEVATEDCVSS v3.1 7.1 HIGH
CPATH-2026-0008Extractable firmware files
Mobile health applicationsHeart Health iOS 2.7.4, Heart Health Android 2.5.1
Qardio
Wearable healthData privacyHIGHCVSS v4.0 6.9 MEDIUM
CPATH-2026-0009Unsigned firmware update
Pneumatic-tube station control panelSwisslog Translogic Nexus Control Panel
Swisslog
General IoTFirmware trust root · Fleet control planeEMERGENCYCVSS v3.1 9.8 CRITICAL
CPATH-2026-0010TLP20 tcpTxThread stack overflow
Pneumatic-tube station control panelSwisslog Translogic Nexus Control Panel
Swisslog
General IoTDevice-control safety · Device availability and recoveryCRITICALCVSS v3.1 9.8 CRITICAL
CPATH-2026-0011One-click remote code execution via malicious deep link
VR sideloading desktop applicationSideQuest before 0.10.35
Meta
Smart glasses / ARPerception-to-action · Account authorityCRITICALCVSS v3.1 8.8 HIGH
CPATH-2026-0012Inception-attack immersive VR hijacking
VR headsetMeta Quest, Meta Quest 2, Meta Quest Pro
Meta
Smart glasses / ARPerception-to-action · Perception privacyCRITICALNo published baseline
CPATH-2026-0013GAZEploit remote keystroke inference
Mixed-reality headset and avatar systemApple Vision Pro, visionOS before 1.3, Persona
Apple
Smart glasses / ARPerception privacy · Account authorityCRITICALCVSS v3.1 5.3 MEDIUM
CPATH-2026-0014Broadcom Wi-Fi over-the-air code execution and denial of service
Mixed-reality headset Wi-Fi stackMicrosoft HoloLens
Microsoft
Smart glasses / ARDevice-control safetyCRITICALCVSS v3.1 8.8 HIGH
CPATH-2026-0015Unauthenticated pairing-API denial of service
Mixed-reality headsetMicrosoft HoloLens 1, Microsoft HoloLens 2
Microsoft
Smart glasses / ARDevice availability and recoveryCRITICALCVSS v3.1 6.5 MEDIUM
CPATH-2026-0016Face-Mic motion-sensor speech eavesdropping
AR/VR headsetOculus Quest, HTC Vive Pro, Google Cardboard with Nexus 6, Google Cardboard with Samsung Galaxy S6
Meta
Smart glasses / ARPerception privacyCRITICALNo published baseline
CPATH-2026-0017Unauthenticated MAVLink remote shell
Drone autopilotPX4 Autopilot v1.16.0 SITL
PX4 / Dronecode
Drone / autonomous systemsDevice-control safetyEMERGENCYCVSS v3.1 9.8 CRITICAL
CPATH-2026-0018VCSEC TPMS integer-overflow remote code execution
Vehicle security controllerTesla Model 3 firmware 2024.8
Tesla
Drone / autonomous systemsPerception-to-actionCRITICALCVSS v3.0 7.5 HIGH
CPATH-2026-0019Gateway firmware signature-validation bypass
Vehicle gateway ECUTesla Model 3 firmware 2023.6
Tesla
Drone / autonomous systemsDevice-control safety · Firmware trust rootCRITICALCVSS v3.0 9 CRITICAL
CPATH-2026-0020QuickTransfer Wi-Fi credential derivation
DJI dronesMavic 3 Pro, Mavic 3, Mavic 3 Classic, Mavic 3 Enterprise, Matrice 300, Matrice M30, Mini 3 Pro
DJI
Drone / autonomous systemsPerception privacyCRITICALCVSS v3.1 6.6 MEDIUM
CPATH-2026-0021Projected phantom-object attacks against driver assistance
Driver-assistance systemTesla Model X Autopilot HW 2.5, Tesla Model X Autopilot HW 3, Mobileye 630
Tesla
Drone / autonomous systemsDevice-control safety · Perception-to-actionCRITICALNo published baseline
CPATH-2026-0022Adaptive GNSS spoofing for drone hijacking
Consumer droneDJI Phantom 3 Standard, DJI Phantom 4, Parrot Bebop 2, 3DR Solo
GNSS multi-vendor
Drone / autonomous systemsPerception-to-action · Device-control safetyCRITICALNo published baseline
CPATH-2026-0023BLE Wi-Fi configuration root takeover
Unitree quadruped and humanoid robotsGo2, B2, G1, H1
Unitree
Robotics / humanoidFleet control planeEMERGENCYCVSS v3.1 8.2 HIGH
CPATH-2026-0024Unauthenticated DDS remote code execution
Quadruped robotUnitree Go2 firmware 1.1.7 through 1.1.11
Unitree
Robotics / humanoidDevice-control safety · Perception privacyCRITICALCVSS v4.0 8.5 HIGH
CPATH-2026-0025Mobile-app database tampering to root code execution
Quadruped robot and companion applicationUnitree Go2 firmware 1.1.7 through 1.1.11, Unitree Go2 Android application
Unitree
Robotics / humanoidPerception privacyCRITICALCVSS v3.1 9.6 CRITICAL
CPATH-2026-0026Undocumented CloudSail remote-access backdoor
Quadruped robotUnitree Go1 firmware 2022_05_11_e0d0e617
Unitree
Robotics / humanoidDevice-control safety · Fleet control planeEMERGENCYCVSS v3.1 6.6 MEDIUM
CPATH-2026-0027Dashboard Server OS command injection
Industrial robot controller softwareUniversal Robots PolyScope 5 before 5.25.1
Universal Robots
Robotics / humanoidDevice-control safety · Fleet control plane · Account authorityEMERGENCYCVSS v3.1 9.8 CRITICAL
CPATH-2026-0028Teleoperation command hijacking and emergency-stop abuse
Teleoperated surgical-robot research platformRaven II
University of Washington / Raven II
Robotics / humanoidPerception-to-action · Device-control safety · Device availability and recoveryCRITICALNo published baseline
CPATH-2026-0029Unauthenticated command injection
Surveillance camera and recorderHikvision IPC E0/E1/E2/E4/E6/E7/G0/G3/G5/H1/H3/H5/H8/R2/R7 families, Hikvision IPD E7/G3/H3/H5/H7/H8/R7 families, Selected Hikvision NVR models
Hikvision
General IoTPerception-to-action · Account authority · Fleet control planeEMERGENCYCVSS v3.1 9.8 CRITICAL
CPATH-2026-0030Authentication bypass
Video-surveillance and intercom devicesDahua IPC-HX3XXX, IPC-HX5XXX, and IPC-HUM7XXX, Dahua VTO75X95X, VTO65XXX, and VTH542XH, Dahua NVR1XXX, NVR2XXX, NVR5XXX, and NVR6XX, Dahua XVR4XXX, XVR5XXX, and XVR7XXX, Selected Dahua PTZ and thermal-camera series
Dahua
General IoTDevice-control safety · Account authorityEMERGENCYCVSS v3.1 9.8 CRITICAL
CPATH-2026-0031Unauthenticated web-management command injection
Wi-Fi routerTP-Link Archer AX21 (AX1800) before 1.1.4 Build 20230219
TP-Link
General IoTAccount authority · Fleet control planeEMERGENCYCVSS v3.1 8.8 HIGH
CPATH-2026-0032Frontend authorization-logic disclosure
Industrial Ethernet switchEDS-508A, PT-508, PT-510, PT-7528, PT-7728, PT-7828, PT-G503, PT-G510, PT-G7728, PT-G7828
Moxa
General IoTAccount authority · Device availability and recovery · Data privacyHIGHCVSS v4.0 9.2 CRITICAL
CPATH-2026-0033Hard-coded smart-lock application credentials
Smart-lock access applicationChirp Access 1.26.0 and earlier
Chirp Systems
General IoTAccount authority · Device-control safetyHIGHCVSS v3.1 4.3 MEDIUM
CPATH-2026-0034Hard-coded-key Wi-Fi password disclosure
Smart lock and Wi-Fi bridgeAugust Smart Lock Pro, August Connect Wi-Fi Bridge App 10.11.0, Connect firmware 2.2.12
August
General IoTData privacyHIGHCVSS v3.1 6.5 MEDIUM
CPATH-2026-0035Unauthenticated, unencrypted RF telemetry
Implantable cardiac devices and telemetry accessoriesConexus RF telemetry protocol, CareLink 2090 Programmer, CareLink and MyCareLink monitors, Amplia, Claria, Compia, Concerto, Consulta, Viva, and Brava CRT-D families, Evera, Maximo II, Mirro, Nayamed, Primo, Protecta, Secura, Virtuoso, and Visia AF ICD families
Medtronic
Medical IoTDevice-control safety · Data privacyCRITICALCVSS v3.1 9.3 CRITICAL
CPATH-2026-0036Unauthenticated RF insulin-delivery control
Insulin pumpMiniMed 508, Paradigm 511, Paradigm 512/712, Paradigm 712E, Paradigm 515/715, Paradigm 522/722, Paradigm 522K/722K, Paradigm 523/723, Paradigm 523K/723K, Paradigm Veo 554/754, Paradigm Veo 554CM/754CM
Medtronic
Medical IoTDevice-control safety · Data privacyCRITICALCVSS v3.0 8.8 HIGH
CPATH-2026-0037RF pairing communication manipulation
Insulin pumpMiniMed 620G, MiniMed 630G, MiniMed 640G, MiniMed 670G
Pump communication accessoryGuardian Link 3, Guardian 2 Link, CareLink USB, Contour Next Link 2.4, Contour Plus Link 2.4
Medtronic
Medical IoTDevice-control safetyCRITICALCVSS v3.1 4.8 MEDIUM
CPATH-2026-0038Shared SSH private-key exposure
Patient-monitoring systemCARESCAPE Telemetry Server, ApexPro Telemetry Server, CARESCAPE Central Station, Clinical Information Center, CARESCAPE B450, B650, and B850 monitors
GE HealthCare
Medical IoTPerception-to-action · Device-control safetyEMERGENCYCVSS v3.1 10 CRITICAL
CPATH-2026-0039Cleartext Wi-Fi credentials and patient data
Infusion pump and wireless battery moduleSIGMA Spectrum Infusion Pump 8.00.01, Spectrum Wireless Battery Module firmware 16 through 22D28
Baxter
Medical IoTAccount authority · Data privacyHIGHCVSS v3.1 4.2 MEDIUM
CPATH-2026-0040Unsigned critical data enables remote dose alteration
Infusion-pump systemInfusomat Space Large Volume Pump, SpaceStation with SpaceCom2 before 012U000062, Battery Pack SP with Wi-Fi
B. Braun
Medical IoTDevice-control safety · Data privacyCRITICALCVSS v3.1 10 CRITICAL