Alpsalpine manufactures a focused line of industrial networking and embedded control appliances, notably the ILX-507 and ILX-F509 series, where vulnerability disclosures cluster around memory-safety and command-injection risks endemic to embedded firmware. The recurring weakness classes—stack-based buffer overflows, OS command injection, sensitive-information exposure, certificate-validation flaws, and code injection—reflect the parsing and privilege-escalation attack surface typical of remotely manageable industrial devices. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Alpsalpine over time
Signals from CVEs in this vendor scope (15 CVEs).
15 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-8480HIGH Alpine iLX-507 Command Injection Remote Code Execution. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Alpine iLX-507 d | Aug 1, 2025 | 8.0 | 26 | NO | NO |
CVE-2025-8476HIGH Alpine iLX-507 TIDAL Improper Certificate Validation Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Alpi | Aug 1, 2025 | 8.0 | 26 | NO | NO |
CVE-2024-23923HIGH Alpine Halo9 prh_l2_sar_data_ind Use-After-Free Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected inst | Sep 28, 2024 | 8.8 | 26 | NO | NO |
CVE-2021-27971HIGH Alps Alpine Touchpad Driver 10.3201.101.215 is vulnerable to DLL Injection. | Jan 31, 2022 | 7.8 | 26 | NO | NO |
CVE-2025-8472HIGH Alpine iLX-507 vCard Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affe | Aug 1, 2025 | 7.4 | 25 | NO | NO |
CVE-2025-8477HIGH Alpine iLX-507 vCard Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affe | Aug 1, 2025 | 7.4 | 24 | NO | NO |
CVE-2025-8474MEDIUM Alpine iLX-507 CarPlay Stack-based Buffer Overflow Code Execution Vulnerability. This vulnerability allows physically present attackers to execute arbitrary code on affected instal | Aug 1, 2025 | 6.8 | 24 | NO | NO |
CVE-2024-23963HIGH This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Alpine Halo9 devices. An attacker must first obtain the ability to pair | Jan 31, 2025 | 8.0 | 24 | NO | NO |
CVE-2025-8475HIGH Alpine iLX-507 AVRCP Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected ins | Aug 1, 2025 | 7.4 | 22 | NO | NO |
CVE-2024-23935HIGH Alpine Halo9 DecodeUTF7 Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected | Sep 28, 2024 | 7.5 | 22 | NO | NO |
Signals from CVEs in this vendor scope (15 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Alpsalpine.
Media articles that mention a CVE ID that affects a product developed by Alpsalpine — matched by CVE ID, not by vendor name.