Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Ailux

First CVE: Mar 5, 2024Active for: 2 yearsTotal CVEs: 12
45.0
VTI Score
High

Ailux's vulnerability profile centers on its IMX6 embedded platform, which appears prominently in the vulnerability landscape despite a narrow product focus. Its disclosed vulnerabilities skew strongly toward critical-severity outcomes and recur through access-control and file-handling weakness classes—including direct request attacks, unrestricted file uploads, unnecessary privilege execution, and improper directory access—that are characteristic of embedded web interfaces and device-management surfaces. Live severity, exploitation activity, and exposure counts are shown alongside this summary.

FAUCET AI Generated
12
Total CVEs
More Total CVEs than 93% of tracked vendors
12.0
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 100% of tracked vendors
8.2
Avg CVSS Score
Higher Avg CVSS Score than 80% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Ailux over time

Volume of CVEsAvg CVSS Base Score
First CVE
Mar 5, 2024
2 years ago
Most Recent CVE
Mar 5, 2024
871 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (12 CVEs).

12 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2023-45600CRITICAL
A CWE-613 “Insufficient Session Expiration” vulnerability in the web application, due to the session cookie “sessionid” lasting two weeks, facilitates session hijacking attacks aga
Mar 5, 20249.827NONO
CVE-2023-5457CRITICAL
A CWE-1269 “Product Released in Non-Release Configuration” vulnerability in the Django web framework used by the web application (due to the “debug” configuration parameter set to
Mar 5, 20249.826NONO
CVE-2023-5456CRITICAL
A CWE-798 “Use of Hard-coded Credentials” vulnerability in the MariaDB database of the web application allows a remote unauthenticated attacker to access the database service and a
Mar 5, 20249.826NONO
CVE-2023-45597CRITICAL
A CWE-1236 “Improper Neutralization of Formula Elements in a CSV File” vulnerability in the “file_configuration” functionality of the web application (concerning the function “expo
Mar 5, 20249.025NONO
CVE-2023-45592CRITICAL
A CWE-250 “Execution with Unnecessary Privileges” vulnerability in the embedded Chromium browser (due to the binary being executed with the “--no-sandbox” option and with root priv
Mar 5, 20249.825NONO
CVE-2023-45595HIGH
A CWE-434 “Unrestricted Upload of File with Dangerous Type” vulnerability in the “file_configuration” functionality of the web application allows a remote authenticated attacker to
Mar 5, 20248.824NONO
CVE-2023-45591HIGH
A CWE-122 “Heap-based Buffer Overflow” vulnerability in the “logger_generic” function of the “Ax_rtu” binary allows a remote authenticated attacker to trigger a memory corruption i
Mar 5, 20248.824NONO
CVE-2023-45599HIGH
A CWE-646 “Reliance on File Name or Extension of Externally-Supplied File” vulnerability in the “iec61850” functionality of the web application allows a remote authenticated attack
Mar 5, 20248.821NONO
CVE-2023-45594MEDIUM
A CWE-552 “Files or Directories Accessible to External Parties” vulnerability in the embedded Chromium browser allows a physical attacker to arbitrarily download/upload files to/fr
Mar 5, 20246.819NONO
CVE-2023-45593MEDIUM
A CWE-184 “Incomplete List of Disallowed Inputs” vulnerability in the embedded Chromium browser (concerning the handling of alternative URLs, other than “ http://localhost” ) allow
Mar 5, 20246.819NONO
View all 12 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products12 CVEs
33%
25%
42%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network10 (83.3%)
Unknown0 (0.0%)
Physical2 (16.7%)
Adjacent Network0 (0.0%)
Attack Complexity
Low12 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None11 (91.7%)
Unknown0 (0.0%)
Required1 (8.3%)
Privileges Required
Low4 (33.3%)
High0 (0.0%)
None8 (66.7%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (12 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Ailux.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Ailux — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Ailux's Products

View all 1 CNAs →

Top CWEs