Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Digi International Inc.

First CVE: Apr 27, 2004Active for: 22 yearsTotal CVEs: 25
41.4
VTI Score
High

Digi International manufactures industrial-grade cellular and networking devices—including transport and connectivity platforms such as the Transport WR series and ConnectPort line—that operate in mission-critical infrastructure and remote-access deployments where firmware and embedded software control network behavior. Vulnerabilities affecting the vendor skew toward serious outcomes, with an elevated share reaching critical severity, and a meaningful tendency toward public exploit availability across its product portfolio. The recurring weakness classes, including cross-site scripting, missing authentication controls, out-of-bounds writes, dangerous file uploads, and authentication bypass mechanisms, reflect the web-management interfaces and embedded authentication challenges inherent to remotely administered edge devices. Defenders should prioritize patching exposed instances of these devices and restrict management access to trusted networks, as firmware updates for industrial and long-deployed devices often lag behind release cycles. Current exploitation activity and exposure counts are shown alongside this summary.

FAUCET AI Generated
25
Total CVEs
More Total CVEs than 97% of tracked vendors
0.0
Avg CVEs / Product / Year
Bottom 1%
7.8
Avg CVSS Score
Higher Avg CVSS Score than 74% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Digi International Inc. over time

Volume of CVEsAvg CVSS Base Score
First CVE
Apr 27, 2004
22 years ago
Most Recent CVE
Dec 9, 2024
593 days ago

Self-Reporting Analysis

Of all the CVEs published by Digi International Inc. as a CNA, 0.0% affect products that Digi International Inc. develops as a vendor.

100.0%
Self-reported: 0 (0.0%)
Third-party: 4 (100.0%)

Of all the CVEs published that affect products developed by Digi International Inc., 0.0% are self-published by Digi International Inc. as a CNA.

100.0%
Self-published: 0 (0.0%)
Other CNAs: 25 (100.0%)

Products(86 total)

Top CVEs

Signals from CVEs in this vendor scope (25 CVEs).

25 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2018-20162CRITICAL
Digi TransPort LR54 4.4.0.26 and possible earlier devices have Improper Input Validation that allows users with 'super' CLI access privileges to bypass a restricted shell and execu
Mar 21, 20199.932NONO
CVE-2022-2634CRITICAL
An attacker may be able to execute malicious actions due to the lack of device access protections and device permissions when using the web application. This could lead to uploadin
Aug 10, 20229.831NONO
CVE-2021-35978CRITICAL
An issue was discovered in Digi TransPort DR64, SR44 VC74, and WR. The ZING protocol allows arbitrary remote command execution with SUPER privileges. This allows an attacker (with
Dec 10, 20219.830NONO
CVE-2020-10136MEDIUM
IP-in-IP protocol specifies IP Encapsulation within IP standard (RFC 2003, STD 1) that decapsulate and route IP-in-IP traffic is vulnerable to spoofing, access-control bypass and o
Jun 2, 20205.330NONO
CVE-2021-36767CRITICAL
In Digi RealPort through 4.10.490, authentication relies on a challenge-response mechanism that gives access to the server password, making the protection ineffective. An attacker
Oct 8, 20219.829NONO
CVE-2021-35977CRITICAL
An issue was discovered in Digi RealPort for Windows through 4.8.488.0. A buffer overflow exists in the handling of ADDP discovery response messages. This could result in arbitrary
Oct 8, 20219.829NONO
CVE-2021-38412CRITICAL
Properly formatted POST requests to multiple resources on the HTTP and HTTPS web servers of the Digi PortServer TS 16 Rack device do not require authentication or authentication to
Sep 17, 20219.829NONO
CVE-2019-18859MEDIUM
Digi AnywhereUSB 14 allows XSS via a link for the Digi Page.
Jan 9, 20206.129NOYES
CVE-2023-4299HIGH
Digi RealPort Protocol is vulnerable to a replay attack that may allow an attacker to bypass authentication to access connected equipment.
Aug 31, 20238.126NONO
CVE-2021-37188HIGH
An issue was discovered on Digi TransPort devices through 2021-07-21. An authenticated attacker may load customized firmware (because the bootloader does not verify that it is auth
Dec 10, 20218.826NONO
View all 25 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products25 CVEs
28%
48%
24%
Severity distribution among all CVEs352,427 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local1 (4.0%)
Network19 (76.0%)
Unknown1 (4.0%)
Physical0 (0.0%)
Adjacent Network4 (16.0%)
Attack Complexity
Low22 (88.0%)
High2 (8.0%)
Unknown1 (4.0%)
User Interaction
None21 (84.0%)
Unknown1 (4.0%)
Required3 (12.0%)
Privileges Required
Low6 (24.0%)
High3 (12.0%)
None15 (60.0%)
Unknown1 (4.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (25 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
2 CVEs
8.0% of CVEs· 76th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Digi International Inc..

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Digi International Inc. — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Digi International Inc.'s Products

View all 3 CNAs →

Top CWEs