Digi International manufactures industrial-grade cellular and networking devices—including transport and connectivity platforms such as the Transport WR series and ConnectPort line—that operate in mission-critical infrastructure and remote-access deployments where firmware and embedded software control network behavior. Vulnerabilities affecting the vendor skew toward serious outcomes, with an elevated share reaching critical severity, and a meaningful tendency toward public exploit availability across its product portfolio. The recurring weakness classes, including cross-site scripting, missing authentication controls, out-of-bounds writes, dangerous file uploads, and authentication bypass mechanisms, reflect the web-management interfaces and embedded authentication challenges inherent to remotely administered edge devices. Defenders should prioritize patching exposed instances of these devices and restrict management access to trusted networks, as firmware updates for industrial and long-deployed devices often lag behind release cycles. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Digi International Inc. over time
Of all the CVEs published by Digi International Inc. as a CNA, 0.0% affect products that Digi International Inc. develops as a vendor.
Of all the CVEs published that affect products developed by Digi International Inc., 0.0% are self-published by Digi International Inc. as a CNA.
Signals from CVEs in this vendor scope (25 CVEs).
25 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-20162CRITICAL Digi TransPort LR54 4.4.0.26 and possible earlier devices have Improper Input Validation that allows users with 'super' CLI access privileges to bypass a restricted shell and execu | Mar 21, 2019 | 9.9 | 32 | NO | NO |
CVE-2022-2634CRITICAL An attacker may be able to execute malicious actions due to the lack of device access protections and device permissions when using the web application. This could lead to uploadin | Aug 10, 2022 | 9.8 | 31 | NO | NO |
CVE-2021-35978CRITICAL An issue was discovered in Digi TransPort DR64, SR44 VC74, and WR. The ZING protocol allows arbitrary remote command execution with SUPER privileges. This allows an attacker (with | Dec 10, 2021 | 9.8 | 30 | NO | NO |
CVE-2020-10136MEDIUM IP-in-IP protocol specifies IP Encapsulation within IP standard (RFC 2003, STD 1) that decapsulate and route IP-in-IP traffic is vulnerable to spoofing, access-control bypass and o | Jun 2, 2020 | 5.3 | 30 | NO | NO |
CVE-2021-36767CRITICAL In Digi RealPort through 4.10.490, authentication relies on a challenge-response mechanism that gives access to the server password, making the protection ineffective. An attacker | Oct 8, 2021 | 9.8 | 29 | NO | NO |
CVE-2021-35977CRITICAL An issue was discovered in Digi RealPort for Windows through 4.8.488.0. A buffer overflow exists in the handling of ADDP discovery response messages. This could result in arbitrary | Oct 8, 2021 | 9.8 | 29 | NO | NO |
CVE-2021-38412CRITICAL Properly formatted POST requests to multiple resources on the HTTP and HTTPS web servers of the Digi PortServer TS 16 Rack device do not require authentication or authentication to | Sep 17, 2021 | 9.8 | 29 | NO | NO |
CVE-2019-18859MEDIUM Digi AnywhereUSB 14 allows XSS via a link for the Digi Page. | Jan 9, 2020 | 6.1 | 29 | NO | YES |
CVE-2023-4299HIGH
Digi RealPort Protocol is vulnerable to a replay attack that may allow an attacker to bypass authentication to access connected equipment.
| Aug 31, 2023 | 8.1 | 26 | NO | NO |
CVE-2021-37188HIGH An issue was discovered on Digi TransPort devices through 2021-07-21. An authenticated attacker may load customized firmware (because the bootloader does not verify that it is auth | Dec 10, 2021 | 8.8 | 26 | NO | NO |
Signals from CVEs in this vendor scope (25 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Digi International Inc..
Media articles that mention a CVE ID that affects a product developed by Digi International Inc. — matched by CVE ID, not by vendor name.