Digisol manufactures a narrow line of small-business networking devices, particularly broadband routers and management appliances such as the DG-BR4000NG and DG-HR3400, that often serve as administrative gateways into internal networks. Vulnerabilities affecting the vendor skew toward serious outcomes and frequently acquire public exploit code, concentrating in web-interface weaknesses including cross-site scripting, cross-site request forgery, and buffer-overflow conditions that reflect the embedded firmware environment. Defenders should treat exposed management interfaces on these devices as high-priority targets for inventory and patching; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Digisol over time
Signals from CVEs in this vendor scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-12706CRITICAL DIGISOL DG-BR4000NG devices have a Buffer Overflow via a long Authorization HTTP header. | Jun 24, 2018 | 9.8 | 45 | NO | YES |
CVE-2017-6896HIGH Privilege escalation vulnerability on the DIGISOL DG-HR1400 1.00.02 wireless router enables an attacker to escalate from user privilege to admin privilege just by modifying the Bas | Mar 14, 2017 | 8.8 | 39 | NO | YES |
CVE-2018-12705MEDIUM DIGISOL DG-BR4000NG devices have XSS via the SSID (it is validated only on the client side). | Jun 24, 2018 | 6.1 | 30 | NO | YES |
CVE-2017-6127HIGH Multiple cross-site request forgery (CSRF) vulnerabilities in the access portal on the DIGISOL DG-HR1400 Wireless Router with firmware 1.00.02 allow remote attackers to hijack the | Feb 21, 2017 | 8.8 | 27 | NO | NO |
CVE-2020-35262MEDIUM Cross Site Scripting (XSS) vulnerability in Digisol DG-HR3400 can be exploited via the NTP server name in Time and date module and "Keyword" in URL Filter. | Jan 6, 2021 | 6.1 | 23 | NO | NO |
CVE-2018-14027MEDIUM Digisol Wireless Wifi Home Router HR-3300 allows XSS via the userid or password parameter to the admin login page. | Jul 5, 2019 | 6.1 | 20 | NO | NO |
CVE-2018-12715MEDIUM DIGISOL DG-HR3400 devices have XSS via a modified SSID when the apssid value is unchanged. | Jul 3, 2019 | 6.1 | 17 | NO | NO |
Signals from CVEs in this vendor scope (7 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Digisol.
Media articles that mention a CVE ID that affects a product developed by Digisol — matched by CVE ID, not by vendor name.