Advisories

For CVSS 2.0, 3.0 and 3.2
VDE-2024-032
July 3, 2024, 3:33 PM
There exists a vulnerability in all REX 100 devices with firmware <= 2.2.11 that allows an authenticated attacker to execute arbitrary system commands via GET requests. Update: 03.07.2024 3:30pm …
VDE-2023-043
Oct. 16, 2023, 10:38 AM
A vulnerability in the affected products allows an authenticated, low-privileged attacker to gain unauthorized read access to limited, non-critical device information. The issue arises from improper access validation.
VDE-2023-029
Aug. 17, 2023, 2:00 PM
A stored XXS vulnerability has been found in REX 200 and REX 250 in all versions before 7.3.2.
VDE-2023-008
May 15, 2023, 2:06 PM
Two vulnerabilites have been discovered in myREX24 and myREX24.virtual in all versions through 2.13.3.
VDE-2022-017
May 14, 2025, 3:00 PM
An issue was discovered in myREX24 and myREX24.virtual in all versions through 2.11.2.
VDE-2022-039
Sept. 7, 2022, 12:56 PM
Multiple vulnerabilities have been found in myREX24 and myREX24.virtual.
VDE-2021-058
May 14, 2025, 3:00 PM
An issue was discovered in the myREX24 and myREX24-virtual software in all versions through V2.9.0.
VDE-2021-057
May 14, 2025, 3:00 PM
Multiple Vulnerabilities in a software service of shDIALUP can lead to arbitrary code execution due to improper privilege management. Update A, 2022-03-28 Updated CVSS score from CVE-2021-33527 from 7.8 to …