Skip to content
Signals
NVD · CVE-2026-64604 · In the Linux kernel, the following vulnerability has been resolved: KVM: VMX: Grab vmcs12 on CR8 interception update iff vCPU is in guest mode When updating CR8NVD · CVE-2026-64603 · In the Linux kernel, the following vulnerability has been resolved: platform/x86: intel-hid: Protect ACPI notify handler against recursion Since commit e2ffcda1NVD · CVE-2026-64602 · In the Linux kernel, the following vulnerability has been resolved: iio: adc: spear: Initialize completion before requesting IRQ In the report from Jaeyoung ChuNVD · CVE-2026-64601 · In the Linux kernel, the following vulnerability has been resolved: ALSA: us144mkii: capture_urb_complete: redundant usb_anchor_urb corrupts anchor list on eachCISA KEV · CVE-2026-8037 · Progress LoadMaster Command Injection Vulnerability · Added 2026-08-07 · Due 2026-08-10CISA KEV · CVE-2026-63077 · 9.8 · JetBrains TeamCity Deserialization of Untrusted Data Vulnerability · Added 2026-08-05 · Due 2026-08-08NVD · CVE-2026-64604 · In the Linux kernel, the following vulnerability has been resolved: KVM: VMX: Grab vmcs12 on CR8 interception update iff vCPU is in guest mode When updating CR8NVD · CVE-2026-64603 · In the Linux kernel, the following vulnerability has been resolved: platform/x86: intel-hid: Protect ACPI notify handler against recursion Since commit e2ffcda1NVD · CVE-2026-64602 · In the Linux kernel, the following vulnerability has been resolved: iio: adc: spear: Initialize completion before requesting IRQ In the report from Jaeyoung ChuNVD · CVE-2026-64601 · In the Linux kernel, the following vulnerability has been resolved: ALSA: us144mkii: capture_urb_complete: redundant usb_anchor_urb corrupts anchor list on eachCISA KEV · CVE-2026-8037 · Progress LoadMaster Command Injection Vulnerability · Added 2026-08-07 · Due 2026-08-10CISA KEV · CVE-2026-63077 · 9.8 · JetBrains TeamCity Deserialization of Untrusted Data Vulnerability · Added 2026-08-05 · Due 2026-08-08

Vendors · pepperl-fuchs

pepperl-fuchs

· 5 Critical

Total CVEs

27

Critical

5

Products

230

Search All CVEs →

27

Products (230)

wha-gw-f2d2-0-as-z2-eth firmware8 CVEswha-gw-f2d2-0-as-z2-eth8 CVEswha-gw-f2d2-0-as-z2-eth.eip firmware6 CVEswha-gw-f2d2-0-as-z2-eth.eip6 CVEses8510-xt firmware5 CVEses8510-xte5 CVEsio-link master dr-8-pnio-t5 CVEses75065 CVEses7506 firmware5 CVEses75105 CVEses7510-xt5 CVEses7510-xt firmware5 CVEses7510 firmware5 CVEses9528-xt5 CVEses9528-xtv25 CVEses9528-xtv2 firmware5 CVEses9528 firmware5 CVEsio-link master 4-pnio5 CVEsio-link master 8-eip5 CVEsio-link master 8-eip-l5 CVEsio-link master 8-pnio5 CVEsio-link master 8-pnio-l5 CVEsio-link master dr-8-eip5 CVEsio-link master dr-8-eip-p5 CVEsio-link master dr-8-eip-t5 CVEsio-link master dr-8-pnio5 CVEsio-link master dr-8-pnio-p5 CVEses95285 CVEses9528-xt firmware5 CVEses8510-xt5 CVEses75285 CVEses7528 firmware5 CVEses85085 CVEses8508 firmware5 CVEses8508f5 CVEses8508f firmware5 CVEses8509-xt5 CVEses8509-xt firmware5 CVEses85105 CVEses8510-xte firmware5 CVEses8510 firmware5 CVEsio-link master 4-eip5 CVEsio-link master dr-8-pnio-p firmware4 CVEsio-link master dr-8-eip-t firmware4 CVEsio-link master dr-8-pnio-t firmware4 CVEsio-link master dr-8-pnio firmware4 CVEsio-link master dr-8-eip-p firmware4 CVEsio-link master 4-eip firmware4 CVEsio-link master 8-pnio-l firmware4 CVEsio-link master 4-pnio firmware4 CVEsio-link master 8-pnio firmware4 CVEsio-link master dr-8-eip firmware4 CVEsio-link master 8-eip-l firmware4 CVEsio-link master 8-eip firmware4 CVEsprofinet firmware3 CVEsmodbus router firmware3 CVEsmodbus server firmware3 CVEsmodbus tcp firmware3 CVEsethernet\/ip firmware3 CVEsicdm-rx\/en-2db9\/rj45-din3 CVEsicdm-rx\/en-2st\/rj45-din3 CVEsicdm-rx\/en-4db9\/2rj45-din3 CVEsicdm-rx\/en-db9\/rj45-din3 CVEsicdm-rx\/en-db9\/rj45-pm3 CVEsicdm-rx\/en-st\/rj45-din3 CVEsicdm-rx\/en1-2db9\/rj45-din3 CVEsicdm-rx\/en1-2st\/rj45-din3 CVEsicdm-rx\/en1-4db9\/2rj45-din3 CVEsicdm-rx\/en1-db9\/rj45-din3 CVEsicdm-rx\/en1-db9\/rj45-pm3 CVEsicdm-rx\/en1-st\/rj45-din3 CVEsicdm-rx\/mod-4db9\/2rj45-din3 CVEsicdm-rx\/mod-db9\/rj45-din3 CVEsicdm-rx\/mod-st\/rj45-din3 CVEsicdm-rx\/pn-2db9\/rj45-din3 CVEsicdm-rx\/pn-2st\/rj45-din3 CVEsicdm-rx\/pn-4db9\/2rj45-din3 CVEsicdm-rx\/pn-db9\/rj45-din3 CVEsicdm-rx\/pn-db9\/rj45-pm3 CVEsicdm-rx\/pn-st\/rj45-din3 CVEsicdm-rx\/pn1-2db9\/rj45-din3 CVEsicdm-rx\/pn1-2st\/rj45-din3 CVEsicdm-rx\/pn1-4db9\/2rj45-din3 CVEsicdm-rx\/pn1-db9\/rj45-din3 CVEsicdm-rx\/pn1-db9\/rj45-pm3 CVEsicdm-rx\/pn1-st\/rj45-din3 CVEsicdm-rx\/tcp-16db9\/rj45-rm3 CVEsicdm-rx\/tcp-16rj45\/2rj45-pm3 CVEsicdm-rx\/tcp-16rj45\/rj45-rm3 CVEsicdm-rx\/tcp-2db9\/rj45-din3 CVEsicdm-rx\/tcp-2st\/rj45-din3 CVEsicdm-rx\/tcp-32rj45\/rj45-rm3 CVEsicdm-rx\/tcp-4db9\/2rj45-din3 CVEsicdm-rx\/tcp-4db9\/2rj45-pm3 CVEsicdm-rx\/tcp-8db9\/2rj45-pm3 CVEsicdm-rx\/tcp-db9\/rj45-din3 CVEsicdm-rx\/tcp-db9\/rj45-pm3 CVEsicdm-rx\/tcp-db9\/rj45-pm23 CVEsicdm-rx\/tcp-st\/rj45-din3 CVEsicdm-rx\/tcp socketserver firmware3 CVEseip\/modbus firmware3 CVEsprofinet\/modbus firmware3 CVEsicrl-m-16rj45\/4cp-g-din3 CVEsicrl-m-16rj45\/4cp-g-din firmware3 CVEsicrl-m-8rj45\/4sfp-g-din3 CVEsicrl-m-8rj45\/4sfp-g-din firmware3 CVEswcs firmware2 CVEswha-gw-f2d2-0-as- z2-eth.eip2 CVEswha-gw-f2d2-0-as- z2-eth.eip firmware2 CVEsoit700-f113-b12-cb firmware2 CVEsoit700-f113-b12-cb2 CVEsoit500-f113-b12-cb firmware2 CVEsoit500-f113-b12-cb2 CVEsoit200-f113-b12-cb firmware2 CVEsoit200-f113-b12-cb2 CVEsoit1500-f113-b12-cb firmware2 CVEsoit1500-f113-b12-cb2 CVEspxv100aq-f200-b28-v1d-60111 CVEsbtc12 firmware1 CVEsbtc141 CVEsbtc14 firmware1 CVEsice1-16di-g60l-v1d1 CVEsice1-16di-g60l-v1d firmware1 CVEsice1-16dio-g60l-c1-v1d1 CVEsice1-16dio-g60l-c1-v1d firmware1 CVEsice1-16dio-g60l-v1d1 CVEsice1-16dio-g60l-v1d firmware1 CVEsice1-8di8do-g60l-c1-v1d1 CVEsice1-8di8do-g60l-c1-v1d firmware1 CVEsice1-8di8do-g60l-v1d1 CVEsice1-8di8do-g60l-v1d firmware1 CVEsice1-8iol-g30l-v1d1 CVEsice1-8iol-g30l-v1d firmware1 CVEsice1-8iol-g60l-v1d1 CVEsice1-8iol-g60l-v1d firmware1 CVEsice1-8iol-s2-g60l-v1d1 CVEsice1-8iol-s2-g60l-v1d firmware1 CVEsio-link master firmware1 CVEsohv-f230-b171 CVEsohv-f230-b17 firmware1 CVEsoit500-f113b17-cb1 CVEsoit500-f113b17-cb firmware1 CVEspactware1 CVEspcv100-f200-b17-v1d1 CVEspcv100-f200-b17-v1d-60111 CVEspcv100-f200-b17-v1d-6011-69971 CVEspcv100-f200-b17-v1d-6011-6997 firmware1 CVEspcv100-f200-b17-v1d-6011-82031 CVEspcv100-f200-b17-v1d-6011-8203 firmware1 CVEspcv100-f200-b17-v1d-6011 firmware1 CVEspcv100-f200-b17-v1d firmware1 CVEspcv100-f200-b25-v1d-60111 CVEspcv100-f200-b25-v1d-6011-67201 CVEspcv100-f200-b25-v1d-6011-6720 firmware1 CVEspcv100-f200-b25-v1d-6011 firmware1 CVEspcv50-f200-b17-v1d1 CVEspcv50-f200-b17-v1d firmware1 CVEspcv50-f200-b25-v1d1 CVEspcv50-f200-b25-v1d firmware1 CVEspcv80-f200-b17-v1d1 CVEspcv80-f200-b17-v1d firmware1 CVEspcv80-f200-b25-v1d1 CVEspcv80-f200-b25-v1d firmware1 CVEspgv100-f200-b17-v1d-74771 CVEspgv100-f200-b17-v1d-7477 firmware1 CVEspgv100-f200a-b17-v1d1 CVEspgv100-f200a-b17-v1d firmware1 CVEspgv100a-f200-b28-v1d1 CVEspgv100a-f200-b28-v1d firmware1 CVEspgv100a-f200a-b28-v1d1 CVEspgv100a-f200a-b28-v1d firmware1 CVEspgv100aq-f200-b28-v1d1 CVEspgv100aq-f200-b28-v1d firmware1 CVEspgv100aq-f200a-b28-v1d1 CVEspgv100aq-f200a-b28-v1d firmware1 CVEspgv150i-f200a-b17-v1d1 CVEspgv150i-f200a-b17-v1d firmware1 CVEspha150-f200-b17-v1d1 CVEspha150-f200a-b17-v1d1 CVEspha200-f200-b17-v1d1 CVEspha200-f200a-b17-t-v1d1 CVEspha200-f200a-b17-v1d1 CVEspha300-f200-b17-t-v1d1 CVEspha300-f200-b17-v1d1 CVEspha300-f200a-b17-t-v1d1 CVEspha300-f200a-b17-v1d1 CVEspha400-f200-b17-v1d1 CVEspha400-f200a-b17-t-v1d1 CVEspha400-f200a-b17-v1d1 CVEspha500-f200-b17-v1d1 CVEspha500-f200a-b17-t-v1d1 CVEspha500-f200a-b17-v1d1 CVEspha600-f200-b17-v1d1 CVEspha600-f200a-b17-v1d1 CVEspha700-f200-b17-v1d1 CVEspha800-f200-b17-v1d1 CVEspha firmware1 CVEspxv100-f200-b17-v1d1 CVEspxv100-f200-b17-v1d-36361 CVEspxv100-f200-b17-v1d-3636 firmware1 CVEspxv100-f200-b17-v1d firmware1 CVEspxv100-f200-b25-v1d1 CVEspxv100-f200-b25-v1d firmware1 CVEspxv100a-f200-b28-v1d1 CVEspxv100a-f200-b28-v1d-60111 CVEspxv100a-f200-b28-v1d-6011 firmware1 CVEspxv100a-f200-b28-v1d firmware1 CVEspxv100aq-f200-b28-v1d1 CVEsbtc121 CVEspxv100aq-f200-b28-v1d-6011 firmware1 CVEspxv100aq-f200-b28-v1d firmware1 CVEspxv100i-f200-b25-v1d1 CVEspxv100i-f200-b25-v1d firmware1 CVEsvisunet rm shell1 CVEswcs3b-ls5101 CVEswcs3b-ls510-om1 CVEswcs3b-ls510d1 CVEswcs3b-ls510d-om1 CVEswcs3b-ls510dh1 CVEswcs3b-ls510dh-om1 CVEswcs3b-ls510h1 CVEswcs3b-ls510h-om1 CVEswcs3b-ls6101 CVEswcs3b-ls610-om1 CVEswcs3b-ls610d1 CVEswcs3b-ls610d-om1 CVEswcs3b-ls610dh1 CVEswcs3b-ls610dh-om1 CVEswcs3b-ls610h1 CVEswcs3b-ls610h-om1 CVEs

Recent Vulnerabilities

View all 27
CVE-2024-5849HIGH 7.1

An unauthenticated remote attacker may use a reflected XSS vulnerability to obtain information from a user or reboot the affected device once.

CVE-2024-38502HIGH 7.1

An unauthenticated remote attacker may use stored XSS vulnerability to obtain information from a user or reboot the affected device once.

CVE-2024-38501MEDIUM 6.1

An unauthenticated remote attacker may use a HTML injection vulnerability with limited length to inject malicious HTML code and gain low-privileged access on the affected device.

CVE-2024-6422CRITICAL 9.8

An unauthenticated remote attacker can manipulate the device via Telnet, stop processes, read, delete and change data.

CVE-2024-6421HIGH 7.5

An unauthenticated remote attacker can read out sensitive device information through a incorrectly configured FTP service.

CVE-2021-34565CRITICAL 9.8

In PEPPERL+FUCHS WirelessHART-Gateway 3.0.7 to 3.0.9 the SSH and telnet services are active with hard-coded credentials.

CVE-2021-34564MEDIUM 5.5

Any cookie-stealing vulnerabilities within the application or browser would enable an attacker to steal the user's credentials to the PEPPERL+FUCHS WirelessHART-Gateway 3.0.9.

CVE-2021-34563LOW 3.3

In PEPPERL+FUCHS WirelessHART-Gateway 3.0.8 and 3.0.9 the HttpOnly attribute is not set on a cookie. This allows the cookie's value to be read or set by client-side JavaScript.

CVE-2021-34562MEDIUM 5.4

In PEPPERL+FUCHS WirelessHART-Gateway 3.0.8 it is possible to inject arbitrary JavaScript into the application's response.

CVE-2021-34561HIGH 7.5

In PEPPERL+FUCHS WirelessHART-Gateway <= 3.0.8 serious issue exists, if the application is not externally accessible or uses IP-based access restrictions. Attackers can use DNS Rebinding to bypass any IP or firewall based access restrictions that may be in place, by proxying through their target's browser.

CVE-2021-34560MEDIUM 5.5

In PEPPERL+FUCHS WirelessHART-Gateway <= 3.0.9 a form contains a password field with autocomplete enabled. The stored credentials can be captured by an attacker who gains control over the user's computer. Therefore the user must have logged in at least once.

CVE-2021-34559MEDIUM 5.4

In PEPPERL+FUCHS WirelessHART-Gateway <= 3.0.8 a vulnerability may allow remote attackers to rewrite links and URLs in cached pages to arbitrary strings.

CVE-2021-33555HIGH 7.5

In PEPPERL+FUCHS WirelessHART-Gateway <= 3.0.7 the filename parameter is vulnerable to unauthenticated path traversal attacks, enabling read access to arbitrary files on the server.

CVE-2021-20988HIGH 8.6

In Hilscher rcX RTOS versions prios to V2.1.14.1 the actual UDP packet length is not verified against the length indicated by the packet. This may lead to a denial of service of the affected device.

CVE-2021-20987HIGH 8.6

A denial of service and memory corruption vulnerability was found in Hilscher EtherNet/IP Core V2 prior to V2.13.0.21that may lead to code injection through network or make devices crash without recovery.

CVE-2021-20986HIGH 7.5

A Denial of Service vulnerability was found in Hilscher PROFINET IO Device V3 in versions prior to V3.14.0.7. This may lead to unexpected loss of cyclic communication or interruption of acyclic communication.

CVE-2020-12525HIGH 7.3

M&M Software fdtCONTAINER Component in versions below 3.5.20304.x and between 3.6 and 3.6.20304.x is vulnerable to deserialization of untrusted data in its project storage.

CVE-2020-12514MEDIUM 6.6

Pepperl+Fuchs Comtrol IO-Link Master in Version 1.5.48 and below is prone to a NULL Pointer Dereference that leads to a DoS in discoveryd

CVE-2020-12513HIGH 7.5

Pepperl+Fuchs Comtrol IO-Link Master in Version 1.5.48 and below is prone to an authenticated blind OS Command Injection.

CVE-2020-12512HIGH 7.5

Pepperl+Fuchs Comtrol IO-Link Master in Version 1.5.48 and below is prone to an authenticated reflected POST Cross-Site Scripting

CVE-2020-12511HIGH 8.8

Pepperl+Fuchs Comtrol IO-Link Master in Version 1.5.48 and below is prone to a Cross-Site Request Forgery (CSRF) in the web interface.

CVE-2020-12504CRITICAL 9.8

Improper Authorization vulnerability of Pepperl+Fuchs P+F Comtrol RocketLinx ES7510-XT, ES8509-XT, ES8510-XT, ES9528-XTv2, ES7506, ES7510, ES7528, ES8508, ES8508F, ES8510, ES8510-XTE, ES9528/ES9528-XT (all versions) and ICRL-M-8RJ45/4SFP-G-DIN, ICRL-M-16RJ45/4CP-G-DIN FW 1.2.3 and below has an active TFTP-Service.

CVE-2020-12503HIGH 7.2

Improper Authorization vulnerability of Pepperl+Fuchs P+F Comtrol RocketLinx ES7510-XT, ES8509-XT, ES8510-XT, ES9528-XTv2, ES7506, ES7510, ES7528, ES8508, ES8508F, ES8510, ES8510-XTE, ES9528/ES9528-XT (all versions) and ICRL-M-8RJ45/4SFP-G-DIN, ICRL-M-16RJ45/4CP-G-DIN FW 1.2.3 and below is prone to multiple authenticated command injections.

CVE-2020-12502HIGH 8.8

Improper Authorization vulnerability of Pepperl+Fuchs P+F Comtrol RocketLinx ES7510-XT, ES8509-XT, ES8510-XT, ES9528-XTv2, ES7506, ES7510, ES7528, ES8508, ES8508F, ES8510, ES8510-XTE, ES9528/ES9528-XT (all versions) and ICRL-M-8RJ45/4SFP-G-DIN, ICRL-M-16RJ45/4CP-G-DIN FW 1.2.3 and below is prone to unauthenticated device administration.

CVE-2020-12501CRITICAL 9.8

Improper Authorization vulnerability of Pepperl+Fuchs P+F Comtrol RocketLinx ES7510-XT, ES8509-XT, ES8510-XT, ES9528-XTv2, ES7506, ES7510, ES7528, ES8508, ES8508F, ES8510, ES8510-XTE, ES9528/ES9528-XT (all versions) use undocumented accounts.