Entes' vulnerability footprint centers on its EMG-12 gateway appliance and firmware, reflecting edge-network and authentication-handling challenges typical of small-footprint embedded devices. The durable signal across its disclosures involves sensitive-information exposure, improper authentication, improper input validation, and insecure use of HTTP query strings—weakness classes that recur in remotely accessible network appliances and underscore the importance of inventory and access controls for this product class.
The number and severity of CVEs published that impact products developed by Entes over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-14826CRITICAL Entes EMG12 versions 2.57 and prior The application uses a web interface where it is possible for an attacker to bypass authentication with a specially crafted URL. This could allo | Oct 2, 2018 | 9.8 | 32 | NO | NO |
CVE-2018-14822CRITICAL Entes EMG12 versions 2.57 and prior an information exposure through query strings vulnerability in the web interface has been identified, which may allow an attacker to impersonate | Oct 2, 2018 | 9.8 | 30 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Entes.
Media articles that mention a CVE ID that affects a product developed by Entes — matched by CVE ID, not by vendor name.