Dragino develops a focused line of LoRaWAN gateway products, exemplified by the LG01, that serve as network infrastructure for IoT deployments. The observed vulnerabilities cluster around web-interface access control, recurrently appearing as cross-site request forgery and improper access restrictions to configuration and diagnostic resources, patterns typical of embedded management interfaces. Current severity, exploitation, and exposure metrics are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Dragino over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-45227HIGH The web portal of Dragino Lora LG01 18ed40 IoT v4.3.4 has the directory listing at the URL https://10.10.20.74/lib/. This address has a backup file which can be downloaded without | Dec 12, 2022 | 7.5 | 25 | NO | NO |
Dragino Lora LG01 18ed40 IoT v4.3.4 was discovered to contain a Cross-Site Request Forgery in the logout page. | Dec 12, 2022 | 3.5 | 17 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Dragino.
Media articles that mention a CVE ID that affects a product developed by Dragino — matched by CVE ID, not by vendor name.