Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

M2Team — Vulnerabilities & Security Advisories 20

Browse all 20 CVE security advisories affecting M2Team. AI-powered Chinese analysis, POCs, and references for each vulnerability.

M2Team develops software primarily used in enterprise environments, with their products focusing on system management and remote access solutions. Historically, their vulnerabilities have commonly included remote code execution, cross-site scripting, and privilege escalation flaws. The team has addressed multiple critical security issues, with six CVEs currently documented in their record. While no major public security incidents have been widely reported, their vulnerability history suggests a pattern of input validation weaknesses and insufficient access controls in their software. Security researchers have noted that patches for their issues often arrive with significant delays, leaving exposed systems vulnerable to exploitation for extended periods.

Top products by M2Team: NanaZip
CVE IDTitleCVSSSeverityPublished
CVE-2026-55781 NanaZip: Unbounded memory allocation (DoS) in NanaZip UFS parser via unvalidated fs_bsize/fs_fsize superblock fields — NanaZipCWE-400--2026-07-10
CVE-2026-55780 NanaZip: Uncaught exception / unbounded allocation in NanaZip .NET single-file Extract() via unvalidated entry Size — NanaZipCWE-248--2026-07-10
CVE-2026-55783 NanaZip: NULL pointer dereference in Extract() of all seven NanaZip custom archive handlers when extracting/testing the whole archive — NanaZipCWE-476--2026-07-10
CVE-2026-55782 NanaZip: Unbounded memory allocation (DoS) in NanaZip WebAssembly parser via attacker-controlled section/name length fields — NanaZipCWE-400--2026-07-10
CVE-2026-47223 NanaZip: Heap out-of-bounds read in NanaZip AVB hashtree descriptor parser via 32-bit unsigned integer overflow — NanaZipCWE-125 5.4 Medium2026-06-12
CVE-2026-47224 NanaZip: Heap buffer-overflow read in NanaZip LVM metadata CRC check — NanaZipCWE-125 4.3 Medium2026-06-12
CVE-2026-47222 NanaZip: Heap out-of-bounds read in NanaZip AVB property descriptor parser via unsigned integer underflow — NanaZipCWE-125 5.4 Medium2026-06-12
CVE-2026-44215 NanaZip: Heap out-of-bounds write in NanaZip UFS directory parser — NanaZipCWE-787 4.4 Medium2026-05-12
CVE-2026-42445 NanaZip: Uncontrolled recursion in NanaZip UFS directory traversal causes stack exhaustion — NanaZipCWE-674 3.3 Low2026-05-12
CVE-2026-42444 NanaZip: Unbounded resource consumption in NanaZip littlefs parser via attacker-controlled BlockCount — NanaZipCWE-770 3.3 Low2026-05-12
CVE-2026-42443 NanaZip: Integer divide-by-zero in NanaZip UFS inode offset calculation — NanaZipCWE-369 3.3 Low2026-05-12
CVE-2026-42442 NanaZip: Null-pointer dereference in NanaZip UFS parser when root inode is a symlink — NanaZipCWE-476 3.3 Low2026-05-12
CVE-2026-42355 NanaZip: Uncontrolled recursion in NanaZip Electron ASAR parser causes stack exhaustion — NanaZipCWE-674 3.3 Low2026-05-12
CVE-2026-42446 NanaZip: Stack out-of-bounds read in NanaZip ZealFS bitmap parser — NanaZipCWE-125 4.4 Medium2026-05-12
CVE-2026-27711 NanaZip UFS Archive Parser Memory Corruption via Unvalidated Directory Record Length — NanaZipCWE-125 7.8AIHighAI2026-02-25
CVE-2026-27710 NanaZip .NET Single-File Parser Integer Underflow Leads to Unbounded Allocation (DoS) — NanaZipCWE-191 7.5AIHighAI2026-02-25
CVE-2026-27709 NanaZip .NET Single-File Manifest Parser Vulnerable to Out-of-Bounds Read via Unchecked RelativePathLength — NanaZipCWE-125 9.1AICriticalAI2026-02-25
CVE-2026-27114 NanaZip has ROMFS Archive Infinite Loop — NanaZipCWE-835 7.5 -2026-02-19
CVE-2026-27014 NanZip has ROMFS Archive Infinite Loop / Stack Overflow — NanaZipCWE-674 6.2 -2026-02-19
CVE-2026-26282 NanaZip has DotNet Single file OOB Heap Read — NanaZipCWE-126 7.1 -2026-02-19

This page lists every published CVE security advisory associated with M2Team. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.