Connectize's vulnerability profile centers on a narrow embedded-device product line, primarily its AC21000 G6 access controller and associated firmware. The disclosures skew strongly toward critical-severity outcomes and recur through web-facing and command-injection weakness classes—including cross-site scripting, cross-site request forgery, improper authorization, and OS command injection—that are characteristic of network appliances with insufficient input validation and access controls. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Connectize over time
Signals from CVEs in this vendor scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-24051CRITICAL A client side rate limit issue discovered in Connectize AC21000 G6 641.139.1.1256 allows attackers to gain escalated privileges via brute force style attacks. | Dec 4, 2023 | 9.8 | 30 | NO | NO |
CVE-2023-24052CRITICAL An issue discovered in Connectize AC21000 G6 641.139.1.1256 allows attackers to gain control of the device via the change password functionality as it does not prompt for the curre | Dec 4, 2023 | 9.8 | 27 | NO | NO |
CVE-2023-24049CRITICAL An issue was discovered on Connectize AC21000 G6 641.139.1.1256 allows attackers to gain escalated privileges on the device via poor credential management. | Dec 4, 2023 | 9.8 | 27 | NO | NO |
CVE-2023-24048HIGH Cross Site Request Forgery (CSRF) vulnerability in Connectize AC21000 G6 641.139.1.1256 allows attackers to gain control of the device via crafted GET request to /man_password.htm. | Dec 4, 2023 | 8.8 | 24 | NO | NO |
CVE-2023-24047MEDIUM An Insecure Credential Management issue discovered in Connectize AC21000 G6 641.139.1.1256 allows attackers to gain escalated privileges via use of weak hashing algorithm. | Dec 4, 2023 | 6.8 | 20 | NO | NO |
CVE-2023-24046MEDIUM An issue was discovered on Connectize AC21000 G6 641.139.1.1256 allows attackers to run arbitrary commands via use of a crafted string in the ping utility. | Dec 4, 2023 | 6.8 | 20 | NO | NO |
CVE-2023-24050MEDIUM Cross Site Scripting (XSS) vulnerability in Connectize AC21000 G6 641.139.1.1256 allows attackers to run arbitrary code via crafted string when setting the Wi-Fi password in the ad | Dec 4, 2023 | 5.4 | 18 | NO | NO |
Signals from CVEs in this vendor scope (7 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Connectize.
Media articles that mention a CVE ID that affects a product developed by Connectize — matched by CVE ID, not by vendor name.