Skip to content
Signals
NVD · CVE-2026-64604 · In the Linux kernel, the following vulnerability has been resolved: KVM: VMX: Grab vmcs12 on CR8 interception update iff vCPU is in guest mode When updating CR8NVD · CVE-2026-64603 · In the Linux kernel, the following vulnerability has been resolved: platform/x86: intel-hid: Protect ACPI notify handler against recursion Since commit e2ffcda1NVD · CVE-2026-64602 · In the Linux kernel, the following vulnerability has been resolved: iio: adc: spear: Initialize completion before requesting IRQ In the report from Jaeyoung ChuNVD · CVE-2026-64601 · In the Linux kernel, the following vulnerability has been resolved: ALSA: us144mkii: capture_urb_complete: redundant usb_anchor_urb corrupts anchor list on eachCISA KEV · CVE-2026-20349 · Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) Heap Inspection Vulnerability · Added 2026-08-11 · Due 2026-08-14CISA KEV · CVE-2026-68820 · Microsoft Windows Ancillary Function Driver for WinSock Use-After-Free Vulnerability · Added 2026-08-11 · Due 2026-08-25NVD · CVE-2026-64604 · In the Linux kernel, the following vulnerability has been resolved: KVM: VMX: Grab vmcs12 on CR8 interception update iff vCPU is in guest mode When updating CR8NVD · CVE-2026-64603 · In the Linux kernel, the following vulnerability has been resolved: platform/x86: intel-hid: Protect ACPI notify handler against recursion Since commit e2ffcda1NVD · CVE-2026-64602 · In the Linux kernel, the following vulnerability has been resolved: iio: adc: spear: Initialize completion before requesting IRQ In the report from Jaeyoung ChuNVD · CVE-2026-64601 · In the Linux kernel, the following vulnerability has been resolved: ALSA: us144mkii: capture_urb_complete: redundant usb_anchor_urb corrupts anchor list on eachCISA KEV · CVE-2026-20349 · Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) Heap Inspection Vulnerability · Added 2026-08-11 · Due 2026-08-14CISA KEV · CVE-2026-68820 · Microsoft Windows Ancillary Function Driver for WinSock Use-After-Free Vulnerability · Added 2026-08-11 · Due 2026-08-25

Vendors · korenix

korenix

· 3 Critical

Total CVEs

14

Critical

3

Products

180

Search All CVEs →

14

Products (180)

jetwave 2212s7 CVEsjetwave 2212g firmware7 CVEsjetwave 2212g7 CVEsjetwave 2212s firmware7 CVEsjetwave 2212x firmware7 CVEsjetwave 2212x7 CVEsjetwave 3220 firmware4 CVEsjetwave 32204 CVEsjetnet 5310g4 CVEsjetwave 23114 CVEsjetwave 2311 firmware4 CVEsjetnet 47063 CVEsjetnet 60953 CVEsjetwave 3220 v33 CVEsjetnet 4706f3 CVEsjetwave 3220 v3 firmware3 CVEsjetnet 50103 CVEsjetwave 2460 firmware3 CVEsjetwave 24603 CVEsjetwave 2424 firmware3 CVEsjetwave 2414 firmware3 CVEsjetwave 24143 CVEsjetwave 2411l firmware3 CVEsjetwave 21113 CVEsjetwave 2111 firmware3 CVEsjetwave 2111l3 CVEsjetwave 2111l firmware3 CVEsjetwave 21143 CVEsjetwave 2114 firmware3 CVEsjetwave 2211c3 CVEsjetwave 2211c firmware3 CVEsjetnet 45103 CVEsjetnet 5428g-20sfp3 CVEsjetwave 3420 v33 CVEsjetwave 4221hp-e firmware3 CVEsjetnet 53103 CVEsjetwave 3420 v3 firmware3 CVEsjetwave 2411 firmware3 CVEsjetwave 2411l3 CVEsjetwave 24113 CVEsjetnet 5810g3 CVEsjetwave 4221hp-e3 CVEsjetnet 5612g-4f firmware2 CVEsjetnet 5612gp-4f2 CVEsjetnet 5612gp-4f firmware2 CVEsjetnet 5620g-4c2 CVEsjetnet 5620g-4c firmware2 CVEsjetnet 5628g2 CVEsjetnet 5628g-r2 CVEsjetnet 5728g-24p2 CVEsjetnet 5728g-24p-ac-2dc-eu2 CVEsjetnet 5728g-24p-ac-2dc-eu firmware2 CVEsjetnet 5728g-24p-ac-2dc-us2 CVEsjetnet 5728g-24p-ac-2dc-us firmware2 CVEsjetnet 5810g firmware2 CVEsjetnet 5828g2 CVEsjetnet 6095 firmware2 CVEsjetnet 6528gf-2ac-eu2 CVEsjetnet 6528gf-2ac-eu firmware2 CVEsjetnet 6528gf-2ac-us2 CVEsjetnet 6528gf-2ac-us firmware2 CVEsjetnet 6528gf-2dc242 CVEsjetnet 6528gf-2dc24 firmware2 CVEsjetnet 6528gf-2dc482 CVEsjetnet 6528gf-2dc48 firmware2 CVEsjetnet 6528gf-ac-eu2 CVEsjetnet 6528gf-ac-eu firmware2 CVEsjetnet 6528gf-ac-us2 CVEsjetnet 6528gf-ac-us firmware2 CVEsjetnet 6628x-4f-eu2 CVEsjetnet 6628x-4f-eu firmware2 CVEsjetnet 6628xp-4f-us2 CVEsjetnet 6628xp-4f-us firmware2 CVEsjetnet 6710g2 CVEsjetnet 6710g-hvdc2 CVEsjetnet 6728g-24p-ac-2dc-eu2 CVEsjetnet 6728g-24p-ac-2dc-eu firmware2 CVEsjetnet 6728g-24p-ac-2dc-us2 CVEsjetnet 6728g-24p-ac-2dc-us firmware2 CVEsjetnet 6828gf-2ac-au2 CVEsjetnet 6828gf-2ac-au firmware2 CVEsjetnet 6828gf-2ac-eu2 CVEsjetnet 6828gf-2ac-eu firmware2 CVEsjetnet 6828gf-2ac-us2 CVEsjetnet 6828gf-2ac-us firmware2 CVEsjetnet 6828gf-2dc242 CVEsjetnet 6828gf-2dc24 firmware2 CVEsjetnet 6828gf-2dc482 CVEsjetnet 6828gf-2dc48 firmware2 CVEsjetnet 6828gf-ac-dc24-eu2 CVEsjetnet 6828gf-ac-dc24-eu firmware2 CVEsjetnet 6828gf-ac-dc24-us2 CVEsjetnet 6828gf-ac-dc24-us firmware2 CVEsjetnet 6828gf-ac-us2 CVEsjetnet 6828gf-ac-us firmware2 CVEsjetnet 6910g-m12 hvdc2 CVEsjetnet 7310g-v22 CVEsjetnet 7310g-v2 firmware2 CVEsjetnet 7628x-4f-eu2 CVEsjetnet 7628x-4f-eu firmware2 CVEsjetnet 7628x-4f-us2 CVEsjetnet 7628x-4f-us firmware2 CVEsjetnet 7628xp-4f-eu2 CVEsjetnet 7628xp-4f-eu firmware2 CVEsjetnet 7628xp-4f-us2 CVEsjetnet 7628xp-4f-us firmware2 CVEsjetnet 7714g-m12 hvdc2 CVEsjetnet 7714g-m12 hvdc firmware2 CVEsjetnet 6910g-m12 hvdc firmware2 CVEsjetnet5018g firmware2 CVEsjetnet5310g firmware2 CVEsjetnet5428g-2g-2fx firmware2 CVEsjetnet5628g-r firmware2 CVEsjetnet5628g firmware2 CVEsjetnet5728g-24p firmware2 CVEsjetnet5828g firmware2 CVEsjetnet6710g-hvdc firmware2 CVEsjetnet6710g firmware2 CVEsjetnet 45082 CVEsjetnet 4508-w2 CVEsjetnet 4508-w firmware2 CVEsjetnet 4508 firmware2 CVEsjetnet 4508f-m2 CVEsjetnet 4508f-m firmware2 CVEsjetnet 4508f-mw2 CVEsjetnet 4508f-mw firmware2 CVEsjetnet 4508f-s2 CVEsjetnet 4508f-s firmware2 CVEsjetnet 4508f-sw2 CVEsjetnet 4508f-sw firmware2 CVEsjetnet 4508i-w2 CVEsjetnet 4508i-w firmware2 CVEsjetnet 4508if-m2 CVEsjetnet 4508if-m firmware2 CVEsjetnet 4508if-mw2 CVEsjetnet 4508if-mw firmware2 CVEsjetnet 4508if-s2 CVEsjetnet 4508if-s firmware2 CVEsjetnet 4508if-sw2 CVEsjetnet 4508if-sw firmware2 CVEsjetnet 4510 firmware2 CVEsjetnet 4706 firmware2 CVEsjetnet 4706f firmware2 CVEsjetnet 5010 firmware2 CVEsjetnet 5018g2 CVEsjetnet 5310 firmware2 CVEsjetnet 5310g firmware2 CVEsjetnet 5428g-20sfp firmware2 CVEsjetnet 5428g-2g-2fx2 CVEsjetnet 5612g-4f2 CVEsjetwave 34202 CVEsjetwave 3420 firmware2 CVEsjetport 5601f1 CVEsjetport 5601 firmware1 CVEsjetport 56011 CVEsjetport1 CVEsjetnet4510 firmware1 CVEsjetnet6095 firmware1 CVEsjetnet5810g firmware1 CVEsjetnet5428g-20sfp firmware1 CVEsjetwave 5810g1 CVEsjetwave 5810g firmware1 CVEsjetnet5310 firmware1 CVEsjetnet5010 firmware1 CVEsjetnet4706f firmware1 CVEsjetnet4706 firmware1 CVEsjetwave 45101 CVEsjetwave 4510 firmware1 CVEsjetwave 47061 CVEsjetwave 4706 firmware1 CVEsjetwave 4706f1 CVEsjetwave 4706f firmware1 CVEsjetwave 50101 CVEsjetwave 5010 firmware1 CVEsjetwave 53101 CVEsjetwave 5310 firmware1 CVEsjetwave 5428g-20sfp1 CVEsjetwave 5428g-20sfp firmware1 CVEsjetport web manager1 CVEsjetport 5601f firmware1 CVEs

Recent Vulnerabilities

View all 14
CVE-2023-5376HIGH 8.6

An Improper Authentication vulnerability in Korenix JetNet TFTP allows abuse of this service. This issue affects JetNet devices older than firmware version 2024/01.

CVE-2023-5347CRITICAL 9.8

An Improper Verification of Cryptographic Signature vulnerability in the update process of Korenix JetNet Series allows replacing the whole operating system including Trusted Executables. This issue affects JetNet devices older than firmware version 2024/01.

CVE-2023-23296MEDIUM 6.5

Korenix JetWave 4200 Series 1.3.0 and JetWave 3200 Series 1.6.0 are vulnerable to Denial of Service via /goform/formDefault.

CVE-2023-23295HIGH 8.8

Korenix Jetwave 4200 Series 1.3.0 and JetWave 3000 Series 1.6.0 are vulnerable to Command Injection via /goform/formSysCmd. An attacker an modify the sysCmd parameter in order to execute commands as root.

CVE-2023-23294HIGH 8.8

Korenix JetWave 4200 Series 1.3.0 and JetWave 3000 Series 1.6.0 are vulnerable to Command Injection. An attacker can modify the file_name parameter to execute commands as root.

CVE-2021-39280HIGH 8.8

Certain Korenix JetWave devices allow authenticated users to execute arbitrary code as root via /syscmd.asp. This affects 2212X before 1.9.1, 2212S before 1.9.1, 2212G before 1.8, 3220 V3 before 1.5.1, 3420 V3 before 1.5.1, and 2311 through 2022-01-31.

CVE-2020-12504CRITICAL 9.8

Improper Authorization vulnerability of Pepperl+Fuchs P+F Comtrol RocketLinx ES7510-XT, ES8509-XT, ES8510-XT, ES9528-XTv2, ES7506, ES7510, ES7528, ES8508, ES8508F, ES8510, ES8510-XTE, ES9528/ES9528-XT (all versions) and ICRL-M-8RJ45/4SFP-G-DIN, ICRL-M-16RJ45/4CP-G-DIN FW 1.2.3 and below has an active TFTP-Service.

CVE-2020-12503HIGH 7.2

Improper Authorization vulnerability of Pepperl+Fuchs P+F Comtrol RocketLinx ES7510-XT, ES8509-XT, ES8510-XT, ES9528-XTv2, ES7506, ES7510, ES7528, ES8508, ES8508F, ES8510, ES8510-XTE, ES9528/ES9528-XT (all versions) and ICRL-M-8RJ45/4SFP-G-DIN, ICRL-M-16RJ45/4CP-G-DIN FW 1.2.3 and below is prone to multiple authenticated command injections.

CVE-2020-12502HIGH 8.8

Improper Authorization vulnerability of Pepperl+Fuchs P+F Comtrol RocketLinx ES7510-XT, ES8509-XT, ES8510-XT, ES9528-XTv2, ES7506, ES7510, ES7528, ES8508, ES8508F, ES8510, ES8510-XTE, ES9528/ES9528-XT (all versions) and ICRL-M-8RJ45/4SFP-G-DIN, ICRL-M-16RJ45/4CP-G-DIN FW 1.2.3 and below is prone to unauthenticated device administration.

CVE-2020-12501CRITICAL 9.8

Improper Authorization vulnerability of Pepperl+Fuchs P+F Comtrol RocketLinx ES7510-XT, ES8509-XT, ES8510-XT, ES9528-XTv2, ES7506, ES7510, ES7528, ES8508, ES8508F, ES8510, ES8510-XTE, ES9528/ES9528-XT (all versions) use undocumented accounts.

CVE-2019-9725

The Web manager (aka Commander) on Korenix JetPort 5601 and 5601f devices has Persistent XSS via the Port Alias field under Serial Setting.

CVE-2017-14027

A Use of Hard-coded Credentials issue was discovered in Korenix JetNet JetNet5018G version 1.4, JetNet5310G version 1.4a, JetNet5428G-2G-2FX version 1.4, JetNet5628G-R version 1.4, JetNet5628G version 1.4, JetNet5728G-24P version 1.4, JetNet5828G version 1.1d, JetNet6710G-HVDC version 1.1e, and JetNet6710G version 1.1. The software uses undocumented hard-coded credentials that may allow an attacker to gain remote access.

CVE-2017-14021

A Use of Hard-coded Cryptographic Key issue was discovered in Korenix JetNet JetNet5018G version 1.4, JetNet5310G version 1.4a, JetNet5428G-2G-2FX version 1.4, JetNet5628G-R version 1.4, JetNet5628G version 1.4, JetNet5728G-24P version 1.4, JetNet5828G version 1.1d, JetNet6710G-HVDC version 1.1e, and JetNet6710G version 1.1. An attacker may gain access to hard-coded certificates and private keys allowing the attacker to perform man-in-the-middle attacks.

CVE-2012-4577

The Linux firmware image on (1) Korenix Jetport 5600 series serial-device servers and (2) ORing Industrial DIN-Rail serial-device servers has a hardcoded password of "password" for the root account, which allows remote attackers to obtain administrative access via an SSH session.