Blaauwproducts' vulnerability profile is concentrated in remote kiln-control systems, a specialized industrial-automation domain with limited but strategically important deployment. Its disclosed vulnerabilities skew toward serious outcomes and recur across information-disclosure and access-control weaknesses—path traversal, cleartext storage of credentials, SQL injection, and error-message information leakage—that are characteristic of legacy control software where security hardening was not a primary design focus. Current severity and exploitation status are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Blaauwproducts over time
Signals from CVEs in this vendor scope (9 CVEs).
9 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-18869CRITICAL Leftover Debug Code in Blaauw Remote Kiln Control through v3.00r4 allows a user to execute arbitrary php code via /default.php?idx=17. | May 7, 2020 | 9.8 | 31 | NO | NO |
CVE-2019-18868CRITICAL Blaauw Remote Kiln Control through v3.00r4 allows an unauthenticated attacker to access MySQL credentials in cleartext in /engine/db.inc, /lang/nl.bak, or /lang/en.bak. | May 7, 2020 | 9.8 | 30 | NO | NO |
CVE-2019-18871HIGH A path traversal in debug.php accessed via default.php in Blaauw Remote Kiln Control through v3.00r4 allows an authenticated attacker to upload arbitrary files, leading to arbitrar | May 7, 2020 | 8.8 | 29 | NO | NO |
CVE-2019-18872HIGH Weak password requirements in Blaauw Remote Kiln Control through v3.00r4 allow a user to set short or guessable passwords (e.g., 1 or 1234). | May 7, 2020 | 7.5 | 25 | NO | NO |
CVE-2019-18866HIGH Unauthenticated SQL injection via the username in the login mechanism in Blaauw Remote Kiln Control through v3.00r4 allows a user to extract arbitrary data from the rkc database. | May 7, 2020 | 7.5 | 25 | NO | NO |
CVE-2019-18864HIGH /server-info and /server-status in Blaauw Remote Kiln Control through v3.00r4 allow an unauthenticated attacker to gain sensitive information about the host machine. | May 7, 2020 | 7.5 | 25 | NO | NO |
CVE-2019-18867HIGH Browsable directories in Blaauw Remote Kiln Control through v3.00r4 allow an attacker to enumerate sensitive filenames and locations, including source code. This affects /ajax/, /c | May 7, 2020 | 7.5 | 24 | NO | NO |
CVE-2019-18870MEDIUM A path traversal via the iniFile parameter in excel.php in Blaauw Remote Kiln Control through v3.00r4 allows an authenticated attacker to download arbitrary files from the host mac | May 7, 2020 | 6.5 | 22 | NO | NO |
CVE-2019-18865MEDIUM Information disclosure via error message discrepancies in authentication functions in Blaauw Remote Kiln Control through v3.00r4 allows an unauthenticated attacker to enumerate val | May 7, 2020 | 5.3 | 20 | NO | NO |
Signals from CVEs in this vendor scope (9 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Blaauwproducts.
Media articles that mention a CVE ID that affects a product developed by Blaauwproducts — matched by CVE ID, not by vendor name.