CoolerControl 厂商相关 4 条 CVE 漏洞,含 AI 中文分析、POC、CVSS 评分与受影响产品。
CoolerControl 是一款开源硬件监控与控制软件,主要用于管理散热器、风扇和泵等设备。历史上,该项目曾曝出远程代码执行、权限提升和跨站脚本漏洞,其中 4 条 CVE 记录显示其安全风险主要集中在未经验证的输入处理和权限管理缺陷。用户需关注其权限配置和输入验证机制,以防范潜在攻击。
| CVE ID | タイトル | CVSS | 深刻度 | 公開日 |
|---|---|---|---|---|
| CVE-2026-5302 | Permissive Cross-domain Policy with Untrusted Domains in coolercontrold — coolercontroldCWE-942 | 6.3 | Medium | 2026-04-08 |
| CVE-2026-5300 | Missing Authentication for Critical Function in coolercontrold — coolercontroldCWE-306 | 5.9 | Medium | 2026-04-08 |
| CVE-2026-5301 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in coolercontrol-ui — coolercontrol-uiCWE-79 | 7.6 | High | 2026-04-08 |
| CVE-2026-5208 | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in coolercontrold — coolercontroldCWE-78 | 8.2 | High | 2026-04-08 |
本页汇总了 CoolerControl 厂商截至目前公开的全部 4 条 CVE 漏洞。每条漏洞均包含 CVSS 评分、CWE 弱点分类、受影响产品与参考链接,并附带 AI 生成的中文分析以便快速判断风险。