Altus manufactures embedded storage and data-transfer appliances, including the Hadron Xtorm and Nexto product families, which present a focused vulnerability profile centered on web-interface and firmware-level weaknesses. The durable signal reflects input-handling and access-control issues recurrent in such appliances: cross-site request forgery, OS command injection, and hard-coded credentials. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Altus over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-39244HIGH Authenticated Semi-Blind Command Injection (via Parameter Injection) exists on Altus Nexto, Nexto Xpress, and Hadron Xtorm devices via the getlogs.cgi tcpdump feature. This affects | Aug 23, 2021 | 8.8 | 26 | NO | NO |
CVE-2021-39245HIGH Hardcoded .htaccess Credentials for getlogs.cgi exist on Altus Nexto, Nexto Xpress, and Hadron Xtorm devices. This affects Nexto NX3003 1.8.11.0, Nexto NX3004 1.8.11.0, Nexto NX300 | Aug 23, 2021 | 7.5 | 23 | NO | NO |
CVE-2021-39243MEDIUM Cross-Site Request Forgery (CSRF) exists on Altus Nexto, Nexto Xpress, and Hadron Xtorm devices via any CGI endpoint. This affects Nexto NX3003 1.8.11.0, Nexto NX3004 1.8.11.0, Nex | Aug 23, 2021 | 6.5 | 22 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Altus.
Media articles that mention a CVE ID that affects a product developed by Altus — matched by CVE ID, not by vendor name.