Castlenet's vulnerability footprint centers on a narrow line of wireless networking and bridge products such as the CBW383G2N and CBV38Z4EC series, which serve as access and connectivity infrastructure in small-to-medium deployments. The observed weakness classes—code injection, cross-site scripting, and insufficiently protected credentials—reflect the web-interface and configuration-handling attack surface typical of managed network appliances. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Castlenet over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-20385CRITICAL CastleNet CBV38Z4EC 125.553mp1.39219mp1.899.007, CBV38Z4ECNIT 125.553mp1.39219mp1.899.005ITT, CBW383G4J 37.556mp5.008, and CBW38G4J 37.553mp1.008 devices allow remote attackers to | Dec 23, 2018 | 9.8 | 29 | NO | NO |
CVE-2025-2212MEDIUM A vulnerability was found in Castlenet CBW383G2N up to 20250301. It has been classified as problematic. This affects an unknown part of the file /RgSwInfo.asp. The manipulation of | Mar 11, 2025 | 6.1 | 18 | NO | NO |
CVE-2025-2213MEDIUM A vulnerability was found in Castlenet CBW383G2N up to 20250301. It has been declared as problematic. This vulnerability affects unknown code of the file /wlanPrimaryNetwork.asp of | Mar 11, 2025 | 4.8 | 16 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Castlenet.
Media articles that mention a CVE ID that affects a product developed by Castlenet — matched by CVE ID, not by vendor name.