Especmic's vulnerability footprint centers on a narrow line of network storage and routing appliances, specifically the RS-12N and RT-12N product families, where disclosures cluster around web-interface authentication and input-handling weaknesses. The recurring issues—including cross-site request forgery, improper authentication, cross-site scripting, and authorization flaws—are characteristic of remotely accessible embedded devices with web management surfaces that lack sufficient input validation and session protection. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Especmic over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-27388CRITICAL Improper authentication vulnerability in T&D Corporation and ESPEC MIC CORP. data logger products allows a remote unauthenticated attacker to login to the product as a registered u | May 23, 2023 | 9.8 | 28 | NO | NO |
CVE-2023-27387HIGH Cross-site request forgery (CSRF) in T&D Corporation and ESPEC MIC CORP. data logger products allows a remote unauthenticated attacker to conduct an arbitrary operation by having a | May 23, 2023 | 8.8 | 25 | NO | NO |
CVE-2023-23545MEDIUM Missing authentication for critical function exists in T&D Corporation and ESPEC MIC CORP. data logger products, which may allow a remote unauthenticated attacker to alter the prod | May 23, 2023 | 5.3 | 19 | NO | NO |
CVE-2023-22654MEDIUM Client-side enforcement of server-side security issue exists in T&D Corporation and ESPEC MIC CORP. data logger products, which may lead to an arbitrary script execution on a logge | May 23, 2023 | 5.4 | 19 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Especmic.
Media articles that mention a CVE ID that affects a product developed by Especmic — matched by CVE ID, not by vendor name.