Airangel produces a line of appliance-based remote-access and management products across its HSMX-App family, where the observed vulnerability profile centers on web-interface weaknesses including cross-site request forgery, cross-site scripting, hard-coded credentials, and weak password requirements. Treat this as a compact vendor profile focused on a narrow product range; current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Airangel over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-40520CRITICAL Airangel HSMX Gateway devices through 5.2.04 have Weak SSH Credentials. | Nov 10, 2021 | 9.8 | 32 | NO | NO |
CVE-2021-40521CRITICAL Airangel HSMX Gateway devices through 5.2.04 allow Remote Code Execution. | Nov 10, 2021 | 9.8 | 30 | NO | NO |
CVE-2021-40519CRITICAL Airangel HSMX Gateway devices through 5.2.04 have Hard-coded Database Credentials. | Nov 10, 2021 | 10.0 | 30 | NO | NO |
CVE-2021-40518MEDIUM Airangel HSMX Gateway devices through 5.2.04 allow CSRF. | Nov 10, 2021 | 6.5 | 22 | NO | NO |
CVE-2021-40517MEDIUM Airangel HSMX Gateway devices through 5.2.04 is vulnerable to stored Cross Site Scripting. XSS Payload is placed in the name column of the updates table using database access. | Nov 10, 2021 | 5.4 | 19 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Airangel.
Media articles that mention a CVE ID that affects a product developed by Airangel — matched by CVE ID, not by vendor name.