Barix develops a focused line of network audio streaming and IP communication appliances, with its vulnerability footprint centered on products such as Instreamer and related firmware. The durable signal is rooted in application-layer input-handling issues, particularly cross-site scripting and information disclosure weaknesses, typical of web-facing device management interfaces. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Barix over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-65231MEDIUM Barix Instreamer v04.06 and earlier is vulnerable to Cross Site Scripting (XSS) in the Web UI I/O & Serial configuration page, specifically the CTS close command user-input field w | Dec 8, 2025 | 6.1 | 21 | NO | NO |
CVE-2024-41700HIGH Barix – CWE-200 Exposure of Sensitive Information to an Unauthorized Actor | Aug 20, 2024 | 7.5 | 21 | NO | NO |
CVE-2025-65230MEDIUM Barix Instreamer v04.06 and v04.05 contains a stored cross-site scripting (XSS) vulnerability in the Web UI Configuration Streaming Destination input. | Dec 8, 2025 | 5.4 | 20 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Barix.
Media articles that mention a CVE ID that affects a product developed by Barix — matched by CVE ID, not by vendor name.