Digitus manufactures network-attached storage and related appliances, with vulnerabilities concentrated in products such as the DA-70254 storage device and its InmailX software, presenting a focused but internet-reachable product line. The observed weakness classes span authentication and credential protection alongside input-handling and memory-safety issues characteristic of embedded device firmware and web administration interfaces. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Digitus over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-15062HIGH DIGITUS DA-70254 4-Port Gigabit Network Hub 2.073.000.E0008 devices allow an attacker on the same network to elevate privileges because the administrative password can be discovere | Aug 7, 2020 | 8.8 | 27 | NO | NO |
CVE-2020-15065MEDIUM DIGITUS DA-70254 4-Port Gigabit Network Hub 2.073.000.E0008 devices allow an attacker on the same network to denial-of-service the device via long input values. | Aug 7, 2020 | 6.5 | 23 | NO | NO |
CVE-2020-15063HIGH DIGITUS DA-70254 4-Port Gigabit Network Hub 2.073.000.E0008 devices allow an attacker on the same network to bypass authentication via a web-administration request that lacks a pas | Aug 7, 2020 | 8.8 | 22 | NO | NO |
CVE-2022-27105MEDIUM InMailX Outlook Plugin < 3.22.0101 is vulnerable to Cross Site Scripting (XSS). InMailX Connection names are not sanitzed in the Outlook tab, which allows a local user or network a | Jul 26, 2022 | 5.4 | 19 | NO | NO |
CVE-2020-15064MEDIUM DIGITUS DA-70254 4-Port Gigabit Network Hub 2.073.000.E0008 devices allow an attacker on the same network to conduct persistent XSS attacks by leveraging administrative privileges | Aug 7, 2020 | 4.3 | 18 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Digitus.
Media articles that mention a CVE ID that affects a product developed by Digitus — matched by CVE ID, not by vendor name.