Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Blaauwproducts

First CVE: May 7, 2020Active for: 6 yearsTotal CVEs: 9

Blaauwproducts' vulnerability profile is concentrated in remote kiln-control systems, a specialized industrial-automation domain with limited but strategically important deployment. Its disclosed vulnerabilities skew toward serious outcomes and recur across information-disclosure and access-control weaknesses—path traversal, cleartext storage of credentials, SQL injection, and error-message information leakage—that are characteristic of legacy control software where security hardening was not a primary design focus. Current severity and exploitation status are shown alongside this summary.

FAUCET AI Generated
9
Total CVEs
More Total CVEs than 91% of tracked vendors
9.0
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 99% of tracked vendors
7.8
Avg CVSS Score
Higher Avg CVSS Score than 74% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Blaauwproducts over time

Volume of CVEsAvg CVSS Base Score
First CVE
May 7, 2020
6 years ago
Most Recent CVE
May 7, 2020
2,273 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (9 CVEs).

9 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2019-18869CRITICAL
Leftover Debug Code in Blaauw Remote Kiln Control through v3.00r4 allows a user to execute arbitrary php code via /default.php?idx=17.
May 7, 20209.831NONO
CVE-2019-18868CRITICAL
Blaauw Remote Kiln Control through v3.00r4 allows an unauthenticated attacker to access MySQL credentials in cleartext in /engine/db.inc, /lang/nl.bak, or /lang/en.bak.
May 7, 20209.830NONO
CVE-2019-18871HIGH
A path traversal in debug.php accessed via default.php in Blaauw Remote Kiln Control through v3.00r4 allows an authenticated attacker to upload arbitrary files, leading to arbitrar
May 7, 20208.829NONO
CVE-2019-18872HIGH
Weak password requirements in Blaauw Remote Kiln Control through v3.00r4 allow a user to set short or guessable passwords (e.g., 1 or 1234).
May 7, 20207.525NONO
CVE-2019-18866HIGH
Unauthenticated SQL injection via the username in the login mechanism in Blaauw Remote Kiln Control through v3.00r4 allows a user to extract arbitrary data from the rkc database.
May 7, 20207.525NONO
CVE-2019-18864HIGH
/server-info and /server-status in Blaauw Remote Kiln Control through v3.00r4 allow an unauthenticated attacker to gain sensitive information about the host machine.
May 7, 20207.525NONO
CVE-2019-18867HIGH
Browsable directories in Blaauw Remote Kiln Control through v3.00r4 allow an attacker to enumerate sensitive filenames and locations, including source code. This affects /ajax/, /c
May 7, 20207.524NONO
CVE-2019-18870MEDIUM
A path traversal via the iniFile parameter in excel.php in Blaauw Remote Kiln Control through v3.00r4 allows an authenticated attacker to download arbitrary files from the host mac
May 7, 20206.522NONO
CVE-2019-18865MEDIUM
Information disclosure via error message discrepancies in authentication functions in Blaauw Remote Kiln Control through v3.00r4 allows an unauthenticated attacker to enumerate val
May 7, 20205.320NONO
View all 9 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products9 CVEs
22%
56%
22%
Severity distribution among all CVEs353,173 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network9 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low9 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None9 (100.0%)
Unknown0 (0.0%)
Required0 (0.0%)
Privileges Required
Low2 (22.2%)
High0 (0.0%)
None7 (77.8%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (9 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Blaauwproducts.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Blaauwproducts — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Blaauwproducts's Products

View all 1 CNAs →

Top CWEs