Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Robert Bosch GmbH

First CVE: Jul 6, 2016Active for: 10 yearsTotal CVEs: 108
26.9
VTI Score
Low

Robert Bosch GmbH's vulnerability portfolio spans a large collection of industrial automation and cordless tool products, including the Nexo operating system and a range of cordless nutrunner devices widely used in manufacturing and assembly environments. Vulnerabilities affecting the vendor skew toward serious outcomes, with an elevated share reaching critical severity; however, the exposure reflects the embedded and operational-technology context of these products rather than trends toward public exploitation. The recurring weakness classes—including cross-site scripting, improper access control, path traversal, and uncontrolled search path elements—center on web-interface and file-access handling within industrial control and embedded firmware, areas where legacy design patterns and limited patch-deployment cycles compound the risk. Defenders managing Bosch industrial devices should prioritize inventory and network segmentation; live severity, exploitation status, and exposure counts are shown alongside this summary.

FAUCET AI Generated
108
Total CVEs
More Total CVEs than 99% of tracked vendors
0.0
Avg CVEs / Product / Year
Bottom 1%
7.6
Avg CVSS Score
Higher Avg CVSS Score than 72% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Robert Bosch GmbH over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jul 6, 2016
10 years ago
Most Recent CVE
Feb 18, 2026
156 days ago

Self-Reporting Analysis

Of all the CVEs published by Robert Bosch GmbH as a CNA, 73.4% affect products that Robert Bosch GmbH develops as a vendor.

73.4%
26.6%
Self-reported: 94 (73.4%)
Third-party: 34 (26.6%)

Of all the CVEs published that affect products developed by Robert Bosch GmbH, 87.0% are self-published by Robert Bosch GmbH as a CNA.

87.0%
13.0%
Self-published: 94 (87.0%)
Other CNAs: 14 (13.0%)

Products(347 total)

Top CVEs

Signals from CVEs in this vendor scope (108 CVEs).

108 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2020-6770CRITICAL
Deserialization of Untrusted Data in the BVMS Mobile Video Service (BVMS MVS) allows an unauthenticated remote attacker to execute arbitrary code on the system. This affects Bosch
Feb 7, 20209.832NONO
CVE-2019-11684CRITICAL
Improper Access Control in the RCP+ server of the Bosch Video Recording Manager (VRM) component allows arbitrary and unauthenticated access to a limited subset of certificates, sto
Feb 26, 20219.831NONO
CVE-2019-11898CRITICAL
Unauthorized APE administration privileges can be achieved by reverse engineering one of the APE service tools. The service tool is discontinued with Bosch Access Professional Edit
Sep 12, 20199.931NONO
CVE-2023-48266CRITICAL
The vulnerability allows an unauthenticated remote attacker to perform a Denial-of-Service (DoS) attack or, possibly, obtain Remote Code Execution (RCE) via a crafted network reque
Jan 10, 20249.830NONO
CVE-2021-23853CRITICAL
In Bosch IP cameras, improper validation of the HTTP header allows an attacker to inject arbitrary HTTP headers through crafted URLs.
Jun 9, 20219.830NONO
CVE-2018-19036CRITICAL
An issue was discovered in several Bosch IP cameras for firmware versions 6.32 and higher. A malicious client could potentially succeed in the unauthorized execution of code on the
Dec 17, 20189.830NONO
CVE-2022-32534CRITICAL
The Bosch Ethernet switch PRA-ES8P2S with software version 1.01.05 and earlier was found to be vulnerable to command injection through its diagnostics web interface. This allows ex
Jun 23, 20229.829NONO
CVE-2021-23857CRITICAL
Login with hash: The login routine allows the client to log in to the system not by using the password, but by using the hash of the password. Combined with CVE-2021-23858, this al
Oct 4, 20219.829NONO
CVE-2018-20299CRITICAL
An issue was discovered in several Bosch Smart Home cameras (360 degree indoor camera and Eyes outdoor camera) with firmware before 6.52.4. A malicious client could potentially suc
Dec 19, 20189.829NONO
CVE-2023-48250CRITICAL
The vulnerability allows a remote attacker to authenticate to the web application with high privileges through multiple hidden hard-coded accounts.
Jan 10, 20249.828NONO
View all 108 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products108 CVEs
31%
47%
20%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local12 (11.1%)
Network88 (81.5%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network8 (7.4%)
Attack Complexity
Low100 (92.6%)
High8 (7.4%)
Unknown0 (0.0%)
User Interaction
None73 (67.6%)
Unknown0 (0.0%)
Required35 (32.4%)
Privileges Required
Low22 (20.4%)
High10 (9.3%)
None76 (70.4%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (108 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Robert Bosch GmbH.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Robert Bosch GmbH — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Robert Bosch GmbH's Products

View all 3 CNAs →

Top CWEs