Eltex's vulnerability footprint centers on its ESP-200 embedded service platform and related firmware, a niche networking appliance with a recurring profile of input-validation weaknesses, command-injection issues, hard-coded credentials, and exposure of sensitive information. The exposure pattern reflects the challenges of securing edge-facing infrastructure software where authentication and input-handling rigor are critical defensive layers. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Eltex over time
Signals from CVEs in this vendor scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-9026CRITICAL ELTEX NTP-RG-1402G 1v10 3.25.3.32 devices allow OS command injection via the PING field of the resource ping.cmd. The NTP-2 device is also affected. | Feb 17, 2020 | 9.8 | 31 | NO | NO |
CVE-2020-9027CRITICAL ELTEX NTP-RG-1402G 1v10 3.25.3.32 devices allow OS command injection via the TRACE field of the resource ping.cmd. The NTP-2 device is also affected. | Feb 17, 2020 | 9.8 | 30 | NO | NO |
CVE-2018-15358HIGH An authenticated attacker with low privileges can activate high privileged user and use it to expand attack surface in Eltex ESP-200 firmware version 1.2.0. | Aug 17, 2018 | 8.8 | 28 | NO | NO |
CVE-2018-15356HIGH An authenticated attacker can execute arbitrary code using command ejection in Eltex ESP-200 firmware version 1.2.0. | Aug 17, 2018 | 8.8 | 28 | NO | NO |
CVE-2018-15359HIGH An authenticated attacker with low privileges can use insecure sudo configuration to expand attack surface in Eltex ESP-200 firmware version 1.2.0. | Aug 17, 2018 | 8.8 | 27 | NO | NO |
CVE-2018-15360HIGH An attacker without authentication can login with default credentials for privileged users in Eltex ESP-200 firmware version 1.2.0. | Aug 17, 2018 | 7.3 | 24 | NO | NO |
CVE-2018-15357MEDIUM An authenticated attacker with low privileges can extract password hash information for all users in Eltex ESP-200 firmware version 1.2.0. | Aug 17, 2018 | 6.5 | 22 | NO | NO |
Signals from CVEs in this vendor scope (7 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Eltex.
Media articles that mention a CVE ID that affects a product developed by Eltex — matched by CVE ID, not by vendor name.