Bab Technologie's vulnerability footprint centers on a narrowly scoped embedded networking product, the EIBport, which functions as a gateway and interface device for building automation and control systems. The vendor's disclosures reflect the device's role in real-time industrial communication and protocol translation, where endpoint integrity and secure access are critical to operational continuity. Current exploitation activity, severity distribution, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Bab Technologie over time
Signals from CVEs in this vendor scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-28909CRITICAL BAB TECHNOLOGIE GmbH eibPort V3 prior version 3.9.1 allow unauthenticated attackers to access uncontrolled the login service at /webif/SecurityModule in a brute force attack. The p | Sep 9, 2021 | 9.8 | 31 | NO | NO |
CVE-2021-28913CRITICAL BAB TECHNOLOGIE GmbH eibPort V3 prior version 3.9.1 allow unauthenticated attackers access to /webif/SecurityModule to validate the so called and hard coded unique 'eibPort String' | Sep 9, 2021 | 9.8 | 29 | NO | NO |
CVE-2021-28911CRITICAL BAB TECHNOLOGIE GmbH eibPort V3 prior version 3.9.1 allow unauthenticated attackers access to /tmp path which contains some sensitive data (e.g. device serial number). Having those | Sep 9, 2021 | 9.8 | 29 | NO | NO |
CVE-2021-28910HIGH BAB TECHNOLOGIE GmbH eibPort V3 prior version 3.9.1 contains basic SSRF vulnerability. It allow unauthenticated attackers to request to any internal and external server. | Sep 9, 2021 | 7.5 | 24 | NO | NO |
CVE-2021-28912HIGH BAB TECHNOLOGIE GmbH eibPort V3. Each device has its own unique hard coded and weak root SSH key passphrase known as 'eibPort string'. This is usable and the final part of an attac | Sep 9, 2021 | 7.2 | 23 | NO | NO |
CVE-2020-24573HIGH BAB TECHNOLOGIE GmbH eibPort V3 prior to 3.8.3 devices allow denial of service (Uncontrolled Resource Consumption) via requests to the lighttpd component. | Nov 12, 2020 | 7.5 | 23 | NO | NO |
CVE-2021-28914MEDIUM BAB TECHNOLOGIE GmbH eibPort V3 prior version 3.9.1 allow the user to set a weak password because the strength is shown in configuration tool, but finally not enforced. This is usa | Sep 9, 2021 | 6.5 | 21 | NO | NO |
Signals from CVEs in this vendor scope (7 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Bab Technologie.
Media articles that mention a CVE ID that affects a product developed by Bab Technologie — matched by CVE ID, not by vendor name.