2wcom manufactures the IP-4C industrial control device and related firmware, a focused hardware platform supporting networked operations in specialized environments. The observed vulnerability pattern centers on information-disclosure and access-control weaknesses—exposure of sensitive data to unauthorized actors, improper access control, and improper authorization—reflecting common challenges in embedded systems where authentication and data-boundary enforcement are critical to security posture. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by 2wcom over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-57438MEDIUM The 2wcom IP-4c 2.15.5 device suffers from a Broken Access Control vulnerability. Certain sensitive endpoints are intended to be accessible only after the admin explicitly grants a | Sep 22, 2025 | 6.8 | 22 | NO | NO |
CVE-2025-57433MEDIUM The 2wcom IP-4c 2.15.5 device's web interface includes an information disclosure vulnerability. By sending a crafted POST request to a specific endpoint (/cwi/ajax_request/get_data | Sep 22, 2025 | 6.5 | 22 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by 2wcom.
Media articles that mention a CVE ID that affects a product developed by 2wcom — matched by CVE ID, not by vendor name.