Canaan specializes in application-specific integrated circuit (ASIC) mining hardware and associated firmware, with a narrow but specialized product footprint centered on the Avalon line of cryptocurrency miners. The recurring vulnerability signal involves missing authentication controls on critical device functions, a structural concern for networked mining equipment exposed to administrative access threats. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Canaan over time
Signals from CVEs in this vendor scope (1 CVEs).
1 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-36604HIGH An access control issue in Canaan Avalon ASIC Miner 2020.3.30 and below allows unauthenticated attackers to arbitrarily change user passwords via a crafted POST request. | Sep 1, 2022 | 7.5 | 25 | NO | NO |
Signals from CVEs in this vendor scope (1 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Canaan.
Media articles that mention a CVE ID that affects a product developed by Canaan — matched by CVE ID, not by vendor name.