All 8 CVE vulnerabilities found in WebCtrl, with AI-generated Chinese analysis, references, and POCs.
Vendor: Automated Logic, a Carrier company
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2025-14295 | Automated Logic WebCTRL and Carrier i-Vu Session Fixation CWE-257 | 8.1AI | HighAI | 2026-01-22 |
| CVE-2024-5540 | ALC WebCTRL Carrier i-Vu Reflected Cross-Site Scripting CWE-79 | 6.1 | - | 2025-11-27 |
| CVE-2024-5539 | ALC WebCTRL Carrier i-Vu Access Control Bypass CWE-863 | 7.5 | - | 2025-11-27 |
| CVE-2025-0657 | ALC WebCTRL Carrier i-Vu and Gen5 Controllers Array Index out-of-range CWE-129 | 7.5 | - | 2025-11-27 |
| CVE-2024-8528 | ALC WebCTRL Carrier i-Vu Reflected XSS due to unsanitized parameter CWE-79 | 6.1AI | MediumAI | 2025-11-19 |
| CVE-2024-8527 | ALC WebCTRL Carrier i-Vu Open Redirect via URL parameter CWE-601 | 6.1AI | MediumAI | 2025-11-19 |
| CVE-2024-8525 | Automated Logic WebCTRL and Carrier i-Vu Unrestricted File Upload CWE-434 | 9.8AI | CriticalAI | 2024-11-21 |
| CVE-2024-8526 | Automated Logic WebCTRL and Carrier i-Vu Open Redirect CWE-601 | 6.1AI | MediumAI | 2024-11-21 |
All 8 known CVE vulnerabilities affecting WebCtrl with full Chinese analysis, references, and POCs where available.