Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

GateManager — Vulnerabilities & Security Advisories 40

All 40 CVE vulnerabilities found in GateManager, with AI-generated Chinese analysis, references, and POCs.

This page aggregates known security flaws reported for GateManager, categorizing them by vulnerability type and associated weakness tags. It collects public advisories and technical reports, covering a time range from the product's initial release through its most recent security updates. Here you can track the vendor's advisory history, analyze the prevalence of specific weakness classes, and review the full vulnerability timeline for this gate control system. The aggregation excludes unverified community claims, focusing solely on confirmed disclosures from the vendor and major security researchers. By filtering by date, severity, or vulnerability category, users can quickly identify patterns in the product's security posture. This view supports internal risk assessments and helps teams understand whether recurring weaknesses have been consistently addressed or remain open across multiple releases. No individual CVE identifiers are listed in the summary view; instead, the interface groups issues by affected components and patch status. The data reflects verified reports submitted through official channels, ensuring accuracy and traceability. Users should note that some older entries may reference legacy firmware versions, so cross-referencing release notes is recommended for comprehensive coverage.

Vendor: Secomea

CVE ID Title CVSS Severity Published
CVE-2026-1759 Secomea GateManager 权限处理不当致提权漏洞 CWE-280 6.5 Medium 2026-09-15
CVE-2026-1758 Session Fixation CWE-384 8.3 High 2026-09-15
CVE-2025-14716 Unauthorized access to information CWE-287 6.5 Medium 2026-03-19
CVE-2021-32007 Missing security header: Referrer-Policy URL CWE-200 3.5 Low 2024-12-13
CVE-2024-1969 Heap buffer overflow CWE-120 8.2 High 2024-04-29
CVE-2024-1579 Insufficient seeding of random number generator CWE-335 8.1 High 2024-04-29
CVE-2023-3675 Insufficient input validation when downloading certain file types. CWE-22 6.5 Medium 2024-04-18
CVE-2023-0317 GateManager debug interface is included in non-debug builds CWE-420 4.9 Medium 2023-04-19
CVE-2022-4308 Clear-text passwords in configuration files CWE-256 6.1 Medium 2023-04-19
CVE-2022-2752 Potential vulnerabilities in GM login process CWE-287 5.5 Medium 2022-12-09
CVE-2022-38123 Insufficient validation of plugin files CWE-20 8.7 High 2022-12-06
CVE-2022-25786 GateManager debug interface is included in production builds CWE-420 4.9 Medium 2022-05-04
CVE-2022-25787 GTA URLs issued by LMM WEB API may leak information CWE-598 7.5 High 2022-05-04
CVE-2022-25783 Hacking attempts from logged-in users are not properly logged by GM CWE-778 4.3 Medium 2022-05-04
CVE-2022-25782 Insufficient privilege checks on object access and updates. CWE-274 5.4 Medium 2022-05-04
CVE-2022-25781 Reflected XSS issues in GateManager CWE-79 4.2 Medium 2022-05-04
CVE-2022-25780 Information leak via device availability query function CWE-200 4.3 Medium 2022-05-04
CVE-2022-25779 Insufficient scope checks allows adding unrelated audit log entries CWE-779 4.3 Medium 2022-05-04
CVE-2022-25778 Unload handlers may unintentionally defeat CSRF guards CWE-352 4.2 Medium 2022-05-04
CVE-2021-32009 Missing XSS guards on firmware page CWE-79 5.0 Medium 2022-03-11
CVE-2021-32006 GateManager information leak for LinkManager Users CWE-275 5.0 Medium 2022-03-07
CVE-2021-32008 Logged-in Administrator may get unrestricted file system access CWE-552 9.9 Critical 2022-03-04
CVE-2021-32004 GateManager does not enforce strict hostname matching for WEB server CWE-923 3.7 Low 2021-11-22
CVE-2020-29030 Insufficient CSRF guards CWE-352 8.1 High 2021-03-05
CVE-2020-29028 Reflected XSS issues CWE-79 6.3 Medium 2021-03-05
CVE-2020-29029 XSS issue due to insufficient sanitization of input field CWE-20 7.3 High 2021-03-05
CVE-2020-29032 Add integrity check of GateManager firmware CWE-494 8.4 High 2021-03-05
CVE-2020-29023 CSV Formula Injection possible due to improper fields escaping in GateManager CWE-116 3.5 Low 2021-02-16
CVE-2020-29022 Host Header Injection allowing web cache poisoning attacks CWE-159 5.3 Medium 2021-02-16
CVE-2020-29024 Missing HtppOnly and Secure flags CWE-614 5.3 Medium 2021-02-16

All 40 known CVE vulnerabilities affecting GateManager with full Chinese analysis, references, and POCs where available.