3xlogic develops a focused access-control and electronic identity-card (EIDC) platform under its Infinias product line, with exposure concentrated in authentication and credential-handling mechanisms. The recurring vulnerability classes—authorization bypasses via user-controlled keys, cleartext transmission of sensitive data, cross-site request forgery, improper authentication, and certificate validation weaknesses—reflect the security-sensitive role of access-control systems and the authentication-layer demands of identity verification infrastructure. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by 3xlogic over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-11542CRITICAL 3xLOGIC Infinias eIDC32 2.213 devices with Web 1.107 allow Authentication Bypass via CMD.HTM?CMD= because authentication depends on the client side's interpretation of the <KEY>MYK | Apr 4, 2020 | 9.8 | 29 | NO | NO |
CVE-2021-41847HIGH An issue was discovered in 3xLogic Infinias Access Control through 6.7.10708.0, affecting physical security. Users with login credentials assigned to a specific zone can send modif | Oct 1, 2021 | 8.8 | 27 | NO | NO |
CVE-2019-18651MEDIUM A cross-site request forgery (CSRF) vulnerability in 3xLogic Infinias Access Control through 6.6.9586.0 allows remote attackers to execute malicious and unauthorized actions (e.g., | Nov 14, 2019 | 6.5 | 21 | NO | NO |
CVE-2020-12681HIGH Missing TLS certificate validation on 3xLogic Infinias eIDC32 devices through 3.4.125 allows an attacker to intercept/control the channel by which door lock policies are applied. | Jul 26, 2021 | 7.5 | 19 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by 3xlogic.
Media articles that mention a CVE ID that affects a product developed by 3xlogic — matched by CVE ID, not by vendor name.