Ailux's vulnerability profile centers on its IMX6 embedded platform, which appears prominently in the vulnerability landscape despite a narrow product focus. Its disclosed vulnerabilities skew strongly toward critical-severity outcomes and recur through access-control and file-handling weakness classes—including direct request attacks, unrestricted file uploads, unnecessary privilege execution, and improper directory access—that are characteristic of embedded web interfaces and device-management surfaces. Live severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Ailux over time
Signals from CVEs in this vendor scope (12 CVEs).
12 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-45600CRITICAL A CWE-613 “Insufficient Session Expiration” vulnerability in the web application, due to the session cookie “sessionid” lasting two weeks, facilitates session hijacking attacks aga | Mar 5, 2024 | 9.8 | 27 | NO | NO |
CVE-2023-5457CRITICAL A CWE-1269 “Product Released in Non-Release Configuration” vulnerability in the Django web framework used by the web application (due to the “debug” configuration parameter set to | Mar 5, 2024 | 9.8 | 26 | NO | NO |
CVE-2023-5456CRITICAL A CWE-798 “Use of Hard-coded Credentials” vulnerability in the MariaDB database of the web application allows a remote unauthenticated attacker to access the database service and a | Mar 5, 2024 | 9.8 | 26 | NO | NO |
CVE-2023-45597CRITICAL A CWE-1236 “Improper Neutralization of Formula Elements in a CSV File” vulnerability in the “file_configuration” functionality of the web application (concerning the function “expo | Mar 5, 2024 | 9.0 | 25 | NO | NO |
CVE-2023-45592CRITICAL A CWE-250 “Execution with Unnecessary Privileges” vulnerability in the embedded Chromium browser (due to the binary being executed with the “--no-sandbox” option and with root priv | Mar 5, 2024 | 9.8 | 25 | NO | NO |
CVE-2023-45595HIGH A CWE-434 “Unrestricted Upload of File with Dangerous Type” vulnerability in the “file_configuration” functionality of the web application allows a remote authenticated attacker to | Mar 5, 2024 | 8.8 | 24 | NO | NO |
CVE-2023-45591HIGH A CWE-122 “Heap-based Buffer Overflow” vulnerability in the “logger_generic” function of the “Ax_rtu” binary allows a remote authenticated attacker to trigger a memory corruption i | Mar 5, 2024 | 8.8 | 24 | NO | NO |
CVE-2023-45599HIGH A CWE-646 “Reliance on File Name or Extension of Externally-Supplied File” vulnerability in the “iec61850” functionality of the web application allows a remote authenticated attack | Mar 5, 2024 | 8.8 | 21 | NO | NO |
CVE-2023-45594MEDIUM A CWE-552 “Files or Directories Accessible to External Parties” vulnerability in the embedded Chromium browser allows a physical attacker to arbitrarily download/upload files to/fr | Mar 5, 2024 | 6.8 | 19 | NO | NO |
CVE-2023-45593MEDIUM A CWE-184 “Incomplete List of Disallowed Inputs” vulnerability in the embedded Chromium browser (concerning the handling of alternative URLs, other than “ http://localhost” ) allow | Mar 5, 2024 | 6.8 | 19 | NO | NO |
Signals from CVEs in this vendor scope (12 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Ailux.
Media articles that mention a CVE ID that affects a product developed by Ailux — matched by CVE ID, not by vendor name.