Assaabloy's vulnerability profile centers on a range of physical access-control and smart-lock products spanning its Control ID and Yale brands, including credential readers, wireless controllers, and networked door locks that gate entry to buildings and secured spaces. Vulnerabilities affecting the vendor skew strongly toward critical severity and recur through foundational security weaknesses including SQL injection, inadequate encryption, authorization bypass via user-controlled keys, and cleartext storage of sensitive credentials—flaws that directly compromise authentication and access governance in deployed systems. Defenders should prioritize patches for internet-reachable or network-connected access-control appliances; live severity and current exposure metrics are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Assaabloy over time
Signals from CVEs in this vendor scope (19 CVEs).
19 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-2043CRITICAL A vulnerability, which was classified as problematic, was found in Control iD RHiD 23.3.19.0. This affects an unknown part of the file /v2/customerdb/operator.svc/a of the componen | Apr 14, 2023 | 9.8 | 31 | NO | NO |
CVE-2023-33367CRITICAL A SQL injection vulnerability exists in Control ID IDSecure 4.7.26.0 and prior, allowing unauthenticated attackers to write PHP files on the server's root directory, resulting in r | Aug 5, 2023 | 9.8 | 28 | NO | NO |
CVE-2025-49851CRITICAL ControlID iDSecure On-premises versions 4.7.48.0 and prior are vulnerable to an improper authentication vulnerability which could allow an attacker to bypass authentication and gai | Jun 24, 2025 | 9.8 | 27 | NO | NO |
CVE-2020-23826HIGH The Yale WIPC-303W 2.21 through 2.31 camera is vulnerable to remote command execution (RCE) through command injection via the HTTP API. NOTE: This may be a duplicate of CVE-2020-10 | Jan 26, 2021 | 8.8 | 27 | NO | NO |
CVE-2025-49853CRITICAL ControlID iDSecure On-premises versions 4.7.48.0 and prior are vulnerable to SQL injections which could allow an attacker to leak arbitrary information and insert arbitrary SQL syn | Jun 24, 2025 | 9.1 | 26 | NO | NO |
CVE-2026-3315HIGH Incorrect Default Permissions, : Execution with Unnecessary Privileges, : Incorrect Permission Assignment for Critical Resource vulnerability in ASSA ABLOY Visionline on Windows al | Mar 10, 2026 | 7.8 | 25 | NO | NO |
CVE-2023-33371CRITICAL Control ID IDSecure 4.7.26.0 and prior uses a hardcoded cryptographic key in order to sign and verify JWT session tokens, allowing attackers to sign arbitrary session tokens and by | Aug 3, 2023 | 9.8 | 25 | NO | NO |
CVE-2023-33369CRITICAL A path traversal vulnerability exists in Control ID IDSecure 4.7.26.0 and prior, allowing attackers to delete arbitrary files on IDSecure filesystem, causing a denial of service. | Aug 3, 2023 | 9.1 | 24 | NO | NO |
CVE-2020-10176CRITICAL ASSA ABLOY Yale WIPC-301W 2.x.2.29 through 2.x.2.43_p1 devices allow Eval Injection of commands. | May 7, 2020 | 9.8 | 24 | NO | NO |
CVE-2025-49852HIGH ControlID iDSecure On-premises versions 4.7.48.0 and prior are vulnerable to a server-side request forgery vulnerability which could allow an unauthenticated attacker to retrieve i | Jun 24, 2025 | 7.5 | 21 | NO | NO |
Signals from CVEs in this vendor scope (19 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Assaabloy.
Media articles that mention a CVE ID that affects a product developed by Assaabloy — matched by CVE ID, not by vendor name.