Controlbyweb manufactures embedded industrial control and remote-management devices, with its vulnerability footprint concentrated in firmware and web interfaces for products such as the X-320M-I and X-301-24I series. The recurring disclosures center on web application weaknesses including cross-site scripting and code injection, reflecting input-handling challenges common to management interfaces with limited development resources.
The number and severity of CVEs published that impact products developed by Controlbyweb over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-23551CRITICAL
Control By Web X-600M devices run Lua scripts and are vulnerable to code injection, which could allow an attacker to remotely execute arbitrary code.
| Feb 13, 2023 | 9.8 | 29 | NO | NO |
CVE-2023-23553MEDIUM
Control By Web X-400 devices are vulnerable to a cross-site scripting attack, which could result in private and session information being transferred to the attacker.
| Feb 13, 2023 | 6.1 | 21 | NO | NO |
CVE-2018-18881MEDIUM A Denial of Service (DOS) issue was discovered in ControlByWeb X-320M-I Web-Enabled Instrumentation-Grade Data Acquisition module 1.05 with firmware revision v1.05. An authenticate | Mar 21, 2019 | 6.5 | 21 | NO | NO |
CVE-2023-6333MEDIUM
The affected ControlByWeb Relay products are vulnerable to a stored cross-site scripting vulnerability, which could allow an attacker to inject arbitrary scripts into the endpoint | Dec 7, 2023 | 5.4 | 18 | NO | NO |
CVE-2018-18882MEDIUM A stored cross-site scripting (XSS) issue was discovered in ControlByWeb X-320M-I Web-Enabled Instrumentation-Grade Data Acquisition module 1.05 with firmware revision v1.05. An au | Mar 21, 2019 | 5.4 | 18 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Controlbyweb.
Media articles that mention a CVE ID that affects a product developed by Controlbyweb — matched by CVE ID, not by vendor name.