Ave's vulnerability footprint centers on industrial and embedded networking equipment, including web-based switches and firmware across product lines such as the 53AB-WBS series and DominaPlus, with a durable pattern of authentication and credential-handling weaknesses. The recurring exposure reflects the security design challenges typical of embedded control systems where authentication mechanisms and credential protection remain structural concerns for defenders managing these devices.
The number and severity of CVEs published that impact products developed by Ave over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-21991CRITICAL AVE DOMINAplus <=1.10.x suffers from an authentication bypass vulnerability due to missing control check when directly calling the autologin GET parameter in changeparams.php scrip | Apr 28, 2021 | 9.8 | 28 | NO | NO |
CVE-2020-21994CRITICAL AVE DOMINAplus <=1.10.x suffers from clear-text credentials disclosure vulnerability that allows an unauthenticated attacker to issue a request to an unprotected directory that hos | Apr 28, 2021 | 9.8 | 25 | NO | NO |
CVE-2020-21996HIGH AVE DOMINAplus <=1.10.x suffers from an unauthenticated reboot command execution. Attackers can exploit this issue to cause a denial of service scenario. | Apr 28, 2021 | 7.5 | 24 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Ave.
Media articles that mention a CVE ID that affects a product developed by Ave — matched by CVE ID, not by vendor name.