Blackbox develops a focused line of wireless presentation systems and remote sensor appliances for enterprise environments, with a modest disclosed vulnerability footprint. The observed weakness classes—including information exposure, path traversal, cross-site scripting, OS command injection, and out-of-bounds writes—reflect the input-handling and access-control demands of networked embedded devices and web-facing management interfaces. Current severity, exploitation status, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Blackbox over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-3929CRITICAL The Crestron AM-100 firmware 1.6.0.2, Crestron AM-101 firmware 2.7.0.1, Barco wePresent WiPG-1000P firmware 2.3.0.10, Barco wePresent WiPG-1600W before firmware 2.4.1.19, Extron Sh | Apr 30, 2019 | 9.8 | 99 | YES | YES |
CVE-2019-3930CRITICAL The Crestron AM-100 firmware 1.6.0.2, Crestron AM-101 firmware 2.7.0.1, Barco wePresent WiPG-1000P firmware 2.3.0.10, Barco wePresent WiPG-1600W before firmware 2.4.1.19, Extron Sh | Apr 30, 2019 | 9.8 | 32 | NO | NO |
CVE-2019-15497CRITICAL Black Box iCOMPEL 9.2.3 through 11.1.4, as used in ONELAN Net-Top-Box 9.2.3 through 11.1.4 and other products, has default credentials that allow remote attackers to access devices | Aug 26, 2019 | 9.8 | 31 | NO | NO |
CVE-2022-4636HIGH Black Box KVM Firmware version 3.4.31307 on models ACR1000A-R-R2, ACR1000A-T-R2, ACR1002A-T, ACR1002A-R, and ACR1020A-T is vulnerable to path traversal, which may allow an attacker | Jan 10, 2023 | 7.5 | 25 | NO | NO |
CVE-2016-2311MEDIUM Black Box AlertWerks ServSensor with firmware before SP473, AlertWerks ServSensor Junior with firmware before SP473, AlertWerks ServSensor Junior with PoE with firmware before SP47 | May 30, 2016 | 6.5 | 22 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Blackbox.
Media articles that mention a CVE ID that affects a product developed by Blackbox — matched by CVE ID, not by vendor name.