CVE-2022-40494: Ehang-Io Nps
Critical severity, CVSS 9.8. EPSS: 2.1% chance of exploitation in the next 30 days.
NPS before v0.26.10 was discovered to contain an authentication bypass vulnerability via constantly generating and sending the Auth key and Timestamp parameters.
Affected products
- Ehang-Io Nps: from 0.19.0, up to and including 0.26.10
Published 2022-10-06. Last modified 2026-06-17.