Aten manufactures a focused portfolio of rack-level power-distribution and IP-KVM switching products designed for data-center infrastructure management, presenting an embedded but strategically important attack surface within server and facility environments. The recurring vulnerability classes across its disclosed disclosures—improper access control, missing authorization, insufficiently protected credentials, and resource-allocation weaknesses—reflect the authentication and privilege boundaries that gate access to critical facility and server-management functions. Defenders managing Aten equipment in production should prioritize network isolation of management interfaces and treat authentication weaknesses in this product class as high-risk, since compromise can enable lateral movement and unauthorized infrastructure manipulation. Live severity, exploitation, and current exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Aten over time
Signals from CVEs in this vendor scope (27 CVEs).
27 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-9776HIGH ATEN Unizon writeFileToHttpServletResponse Directory Traversal Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on | Jun 24, 2026 | 7.5 | 33 | NO | NO |
CVE-2026-9779HIGH ATEN Unizon doCryptoHugeFileToFile Improper Verification of Cryptographic Signature Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbit | Jun 24, 2026 | 7.2 | 32 | NO | NO |
CVE-2026-9778HIGH ATEN Unizon ImportDeviceList Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations | Jun 24, 2026 | 7.2 | 31 | NO | NO |
CVE-2026-9777HIGH ATEN Unizon restoreDB Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of ATE | Jun 24, 2026 | 7.2 | 31 | NO | NO |
CVE-2026-9775MEDIUM ATEN Unizon uploadSSL Directory Traversal Arbitrary File Deletion Vulnerability. This vulnerability allows remote attackers to delete arbitrary files on affected installations of A | Jun 24, 2026 | 6.5 | 30 | NO | NO |
CVE-2026-9774MEDIUM ATEN Unizon updateLicense Directory Traversal Arbitrary File Deletion Vulnerability. This vulnerability allows remote attackers to delete arbitrary files on affected installations | Jun 24, 2026 | 6.5 | 30 | NO | NO |
CVE-2025-6685HIGH ATEN eco DC Missing Authorization Privilege Escalation Vulnerability. This vulnerability allows remote attackers to escalate privileges on affected installations of ATEN eco DC. Au | Sep 2, 2025 | 8.8 | 27 | NO | NO |
CVE-2023-43845CRITICAL Aten PE6208 2.3.228 and 2.4.232 have default credentials for the privileged telnet account. The user is not asked to change the credentials after first login. If not changed, attac | May 28, 2024 | 9.8 | 26 | NO | NO |
CVE-2009-1477HIGH The https web interfaces on the ATEN KH1516i IP KVM switch with firmware 1.0.063, the KN9116 IP KVM switch with firmware 1.1.104, and the PN9108 power-control unit have a hardcoded | May 27, 2009 | 10.0 | 26 | NO | NO |
CVE-2009-1473HIGH The (1) Windows and (2) Java client programs for the ATEN KH1516i IP KVM switch with firmware 1.0.063 and the KN9116 IP KVM switch with firmware 1.1.104 do not properly use RSA cry | May 27, 2009 | 10.0 | 25 | NO | NO |
Signals from CVEs in this vendor scope (27 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Aten.
Media articles that mention a CVE ID that affects a product developed by Aten — matched by CVE ID, not by vendor name.