Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Boschrexroth

First CVE: Oct 25, 2023Active for: 3 yearsTotal CVEs: 9

Bosch Rexroth's vulnerability footprint is concentrated in its ctrlX HMI web panel line of industrial control interfaces and associated firmware, which serve as operator terminals and integration points in automation environments. The recurring weakness classes—missing authentication for critical functions, hard-coded credentials, cleartext transmission of sensitive data, and improper access control—reflect the legacy design and integration constraints of embedded control-system web interfaces rather than modern security architecture. Defenders managing these devices should inventory affected models and restrict network exposure of the HMI interfaces; live severity and exploitation counts are shown alongside this summary.

FAUCET AI Generated
9
Total CVEs
More Total CVEs than 91% of tracked vendors
1.5
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 76% of tracked vendors
7.7
Avg CVSS Score
Higher Avg CVSS Score than 74% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Boschrexroth over time

Volume of CVEsAvg CVSS Base Score
First CVE
Oct 25, 2023
2 years ago
Most Recent CVE
Oct 25, 2023
1,003 days ago

Products(6 total)

Top CVEs

Signals from CVEs in this vendor scope (9 CVEs).

9 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2023-46102HIGH
The Android Client application, when enrolled to the AppHub server, connects to an MQTT broker to exchange messages and receive commands to execute on the HMI device. The protoco
Oct 25, 20238.824NONO
CVE-2023-41255HIGH
The vulnerability allows an unprivileged user with access to the subnet of the TPC-110W device to gain a root shell on the device itself abusing the lack of authentication of the
Oct 25, 20238.824NONO
CVE-2023-45851HIGH
The Android Client application, when enrolled to the AppHub server,connects to an MQTT broker without enforcing any server authentication.  This issue allows an attacker to fo
Oct 25, 20238.823NONO
CVE-2023-45321HIGH
The Android Client application, when enrolled with the define method 1 (the user manually inserts the server ip address), use HTTP protocol to retrieve sensitive information (ip a
Oct 25, 20238.823NONO
CVE-2023-45220HIGH
The Android Client application, when enrolled with the define method 1(the user manually inserts the server ip address), use HTTP protocol to retrieve sensitive information (ip ad
Oct 25, 20238.823NONO
CVE-2023-41372HIGH
The vulnerability allows an unprivileged (untrusted) third- party application to arbitrary modify the server settings of the Android Client application, inducing it to connect to a
Oct 25, 20237.822NONO
CVE-2023-43488HIGH
The vulnerability allows a low privileged (untrusted) application to modify a critical system property that should be denied, in order to enable the ADB (Android Debug Bridge) pro
Oct 25, 20237.821NONO
CVE-2023-45844MEDIUM
The vulnerability allows a low privileged user that have access to the device when locked in Kiosk mode to install an arbitrary Android application and leverage it to have access t
Oct 25, 20236.820NONO
CVE-2023-41960LOW
The vulnerability allows an unprivileged(untrusted) third-party application to interact with a content-provider unsafely exposed by the Android Agent application, potentially modif
Oct 25, 20233.314NONO
View all 9 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products9 CVEs
11%
11%
78%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
LowMediumHigh
Attack Vector
Local3 (33.3%)
Network0 (0.0%)
Unknown0 (0.0%)
Physical1 (11.1%)
Adjacent Network5 (55.6%)
Attack Complexity
Low9 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None9 (100.0%)
Unknown0 (0.0%)
Required0 (0.0%)
Privileges Required
Low3 (33.3%)
High0 (0.0%)
None6 (66.7%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (9 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Boschrexroth.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Boschrexroth — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Boschrexroth's Products

View all 1 CNAs →

Top CWEs