Beeline's vulnerability footprint centers on its Smart Box and Pro 2 device lines and their associated firmware, representing a compact portfolio in the embedded device space. The observed exposure clusters around web-application and command-injection weaknesses—including cross-site request forgery, cross-site scripting, OS command injection, and code-integrity issues—that are characteristic of firmware-driven appliances with web management interfaces. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Beeline over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-12246HIGH Beeline Smart Box 2.0.38 routers allow "Advanced settings > Other > Diagnostics" OS command injection via the Ping ping_ipaddr parameter, the Nslookup nslookup_ipaddr parameter, or | Apr 29, 2020 | 8.8 | 28 | NO | NO |
CVE-2021-41426HIGH Beeline Smart box 2.0.38 is vulnerable to Cross Site Request Forgery (CSRF) via mgt_end_user.htm. | Nov 10, 2021 | 8.8 | 26 | NO | NO |
CVE-2016-6564HIGH Android devices with code from Ragentek contain a privileged binary that performs over-the-air (OTA) update checks. Additionally, there are multiple techniques used to hide the exe | Jul 13, 2018 | 8.1 | 23 | NO | NO |
CVE-2021-41427MEDIUM Beeline Smart Box 2.0.38 is vulnerable to Cross Site Scripting (XSS) via the choose_mac parameter to setup.cgi. | Nov 10, 2021 | 6.1 | 21 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Beeline.
Media articles that mention a CVE ID that affects a product developed by Beeline — matched by CVE ID, not by vendor name.