Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Assaabloy

First CVE: Jul 15, 2019Active for: 7 yearsTotal CVEs: 19
29.7
VTI Score
Low

Assaabloy's vulnerability profile centers on a range of physical access-control and smart-lock products spanning its Control ID and Yale brands, including credential readers, wireless controllers, and networked door locks that gate entry to buildings and secured spaces. Vulnerabilities affecting the vendor skew strongly toward critical severity and recur through foundational security weaknesses including SQL injection, inadequate encryption, authorization bypass via user-controlled keys, and cleartext storage of sensitive credentials—flaws that directly compromise authentication and access governance in deployed systems. Defenders should prioritize patches for internet-reachable or network-connected access-control appliances; live severity and current exposure metrics are shown alongside this summary.

FAUCET AI Generated
19
Total CVEs
More Total CVEs than 96% of tracked vendors
0.2
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 1% of tracked vendors
7.7
Avg CVSS Score
Higher Avg CVSS Score than 73% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Assaabloy over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jul 15, 2019
7 years ago
Most Recent CVE
Mar 10, 2026
136 days ago

Products(16 total)

Top CVEs

Signals from CVEs in this vendor scope (19 CVEs).

19 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2023-2043CRITICAL
A vulnerability, which was classified as problematic, was found in Control iD RHiD 23.3.19.0. This affects an unknown part of the file /v2/customerdb/operator.svc/a of the componen
Apr 14, 20239.831NONO
CVE-2023-33367CRITICAL
A SQL injection vulnerability exists in Control ID IDSecure 4.7.26.0 and prior, allowing unauthenticated attackers to write PHP files on the server's root directory, resulting in r
Aug 5, 20239.828NONO
CVE-2025-49851CRITICAL
ControlID iDSecure On-premises versions 4.7.48.0 and prior are vulnerable to an improper authentication vulnerability which could allow an attacker to bypass authentication and gai
Jun 24, 20259.827NONO
CVE-2020-23826HIGH
The Yale WIPC-303W 2.21 through 2.31 camera is vulnerable to remote command execution (RCE) through command injection via the HTTP API. NOTE: This may be a duplicate of CVE-2020-10
Jan 26, 20218.827NONO
CVE-2025-49853CRITICAL
ControlID iDSecure On-premises versions 4.7.48.0 and prior are vulnerable to SQL injections which could allow an attacker to leak arbitrary information and insert arbitrary SQL syn
Jun 24, 20259.126NONO
CVE-2026-3315HIGH
Incorrect Default Permissions, : Execution with Unnecessary Privileges, : Incorrect Permission Assignment for Critical Resource vulnerability in ASSA ABLOY Visionline on Windows al
Mar 10, 20267.825NONO
CVE-2023-33371CRITICAL
Control ID IDSecure 4.7.26.0 and prior uses a hardcoded cryptographic key in order to sign and verify JWT session tokens, allowing attackers to sign arbitrary session tokens and by
Aug 3, 20239.825NONO
CVE-2023-33369CRITICAL
A path traversal vulnerability exists in Control ID IDSecure 4.7.26.0 and prior, allowing attackers to delete arbitrary files on IDSecure filesystem, causing a denial of service.
Aug 3, 20239.124NONO
CVE-2020-10176CRITICAL
ASSA ABLOY Yale WIPC-301W 2.x.2.29 through 2.x.2.43_p1 devices allow Eval Injection of commands.
May 7, 20209.824NONO
CVE-2025-49852HIGH
ControlID iDSecure On-premises versions 4.7.48.0 and prior are vulnerable to a server-side request forgery vulnerability which could allow an unauthenticated attacker to retrieve i
Jun 24, 20257.521NONO
View all 19 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products19 CVEs
42%
21%
37%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local1 (5.3%)
Network15 (78.9%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network3 (15.8%)
Attack Complexity
Low17 (89.5%)
High2 (10.5%)
Unknown0 (0.0%)
User Interaction
None18 (94.7%)
Unknown0 (0.0%)
Required1 (5.3%)
Privileges Required
Low5 (26.3%)
High0 (0.0%)
None14 (73.7%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (19 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Assaabloy.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Assaabloy — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Assaabloy's Products

View all 4 CNAs →

Top CWEs