Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Altus

First CVE: Aug 23, 2021Active for: 5 yearsTotal CVEs: 3

Altus manufactures embedded storage and data-transfer appliances, including the Hadron Xtorm and Nexto product families, which present a focused vulnerability profile centered on web-interface and firmware-level weaknesses. The durable signal reflects input-handling and access-control issues recurrent in such appliances: cross-site request forgery, OS command injection, and hard-coded credentials. Live severity, exploitation, and exposure counts are shown alongside this summary.

FAUCET AI Generated
3
Total CVEs
More Total CVEs than 72% of tracked vendors
0.1
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 1% of tracked vendors
7.6
Avg CVSS Score
Higher Avg CVSS Score than 72% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Altus over time

Volume of CVEsAvg CVSS Base Score
First CVE
Aug 23, 2021
4 years ago
Most Recent CVE
Aug 23, 2021
1,795 days ago

Products(30 total)

Top CVEs

Signals from CVEs in this vendor scope (3 CVEs).

3 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2021-39244HIGH
Authenticated Semi-Blind Command Injection (via Parameter Injection) exists on Altus Nexto, Nexto Xpress, and Hadron Xtorm devices via the getlogs.cgi tcpdump feature. This affects
Aug 23, 20218.826NONO
CVE-2021-39245HIGH
Hardcoded .htaccess Credentials for getlogs.cgi exist on Altus Nexto, Nexto Xpress, and Hadron Xtorm devices. This affects Nexto NX3003 1.8.11.0, Nexto NX3004 1.8.11.0, Nexto NX300
Aug 23, 20217.523NONO
CVE-2021-39243MEDIUM
Cross-Site Request Forgery (CSRF) exists on Altus Nexto, Nexto Xpress, and Hadron Xtorm devices via any CGI endpoint. This affects Nexto NX3003 1.8.11.0, Nexto NX3004 1.8.11.0, Nex
Aug 23, 20216.522NONO
View all 3 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products3 CVEs
33%
67%
Severity distribution among all CVEs352,101 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local0 (0.0%)
Network3 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low3 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None2 (66.7%)
Unknown0 (0.0%)
Required1 (33.3%)
Privileges Required
Low1 (33.3%)
High0 (0.0%)
None2 (66.7%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (3 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Altus.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Altus — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Altus's Products

View all 1 CNAs →

Top CWEs