4cstrategies develops Exonaut, a narrowly scoped product that has surfaced vulnerabilities skewing toward critical severity across a recurring pattern of access-control, information-disclosure, and path-traversal weaknesses typical of web applications with insufficient input validation and permission boundaries. These weakness classes—including improper access control, path traversal, and sensitive data exposure in error messages—reflect common risks in the application's handling of user input and file-system operations. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by 4cstrategies over time
Signals from CVEs in this vendor scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-46658CRITICAL An issue was discovered in ExonautWeb in 4C Strategies Exonaut 21.6. There are verbose error messages. | Aug 5, 2025 | 9.8 | 33 | NO | NO |
CVE-2024-55401MEDIUM An issue in 4C Strategies Exonaut before v22.4 allows attackers to execute a directory traversal. | Aug 7, 2025 | 6.5 | 25 | NO | NO |
CVE-2025-46659HIGH An issue was discovered in ExonautWeb in 4C Strategies Exonaut 21.6. Information disclosure can occur via an external HTTPS request. | Aug 6, 2025 | 7.5 | 25 | NO | NO |
CVE-2024-55399MEDIUM 4C Strategies Exonaut before v21.6.2.1-1 was discovered to contain a Server-Side Request Forgery (SSRF). | Aug 6, 2025 | 6.5 | 24 | NO | NO |
CVE-2024-55398MEDIUM 4C Strategies Exonaut before v22.4 was discovered to contain insecure permissions. | Aug 6, 2025 | 6.5 | 24 | NO | NO |
CVE-2024-55402MEDIUM 4C Strategies Exonaut before v22.4 was discovered to contain an access control issue. | Aug 6, 2025 | 5.3 | 21 | NO | NO |
CVE-2025-46660MEDIUM An issue was discovered in 4C Strategies Exonaut 21.6. Passwords, stored in the database, are hashed without a salt. | Aug 6, 2025 | 5.3 | 19 | NO | NO |
Signals from CVEs in this vendor scope (7 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by 4cstrategies.
Media articles that mention a CVE ID that affects a product developed by 4cstrategies — matched by CVE ID, not by vendor name.