Advisories

Für CVSS 2.0, 3.0 und 3.2
VDE-2024-032
Juli 3, 2024, 3:33 nachm.
There exists a vulnerability in all REX 100 devices with firmware <= 2.2.11 that allows an authenticated attacker to execute arbitrary system commands via GET requests. Update: 03.07.2024 3:30pm …
VDE-2023-043
Okt. 16, 2023, 10:38 vorm.
A vulnerability in the affected products allows an authenticated, low-privileged attacker to gain unauthorized read access to limited, non-critical device information. The issue arises from improper access validation.
VDE-2023-029
Aug. 17, 2023, 2:00 nachm.
A stored XXS vulnerability has been found in REX 200 and REX 250 in all versions before 7.3.2.
VDE-2023-008
Mai 15, 2023, 2:06 nachm.
Two vulnerabilites have been discovered in myREX24 and myREX24.virtual in all versions through 2.13.3.
VDE-2022-017
Mai 14, 2025, 3:00 nachm.
An issue was discovered in myREX24 and myREX24.virtual in all versions through 2.11.2.
VDE-2022-039
Sept. 7, 2022, 12:56 nachm.
Multiple vulnerabilities have been found in myREX24 and myREX24.virtual.
VDE-2021-058
Mai 14, 2025, 3:00 nachm.
An issue was discovered in the myREX24 and myREX24-virtual software in all versions through V2.9.0.
VDE-2021-057
Mai 14, 2025, 3:00 nachm.
Multiple Vulnerabilities in a software service of shDIALUP can lead to arbitrary code execution due to improper privilege management. Update A, 2022-03-28 Updated CVSS score from CVE-2021-33527 from 7.8 to …