Evenroute's vulnerability footprint centers on its IQRouter product line and associated firmware, a narrowly scoped but prominently positioned network appliance. The vendor's disclosures skew strongly toward critical-severity outcomes and recur through authentication and access-control weakness classes—including improper authentication, OS command injection, missing authorization, and weak password requirements—alongside information-disclosure flaws that reflect the sensitive role of network routing and management interfaces. Defenders should treat this vendor's advisories as high-priority for any deployed IQRouter instances; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Evenroute over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-11963CRITICAL IQrouter through 3.3.1, when unconfigured, has multiple remote code execution vulnerabilities in the web-panel because of Bash Shell Metacharacter Injection. Note: The vendor claim | Apr 21, 2020 | 9.8 | 30 | NO | NO |
CVE-2020-11967CRITICAL In IQrouter through 3.3.1, remote attackers can control the device (restart network, reboot, upgrade, reset) because of Incorrect Access Control. Note: The vendor claims that this | Apr 21, 2020 | 9.8 | 25 | NO | NO |
CVE-2020-11966CRITICAL In IQrouter through 3.3.1, the Lua function reset_password in the web-panel allows remote attackers to change the root password arbitrarily. Note: The vendor claims that this vulne | Apr 21, 2020 | 9.8 | 25 | NO | NO |
CVE-2020-11968HIGH In the web-panel in IQrouter through 3.3.1, remote attackers can read system logs because of Incorrect Access Control. Note: The vendor claims that this vulnerability can only occu | Apr 21, 2020 | 7.5 | 24 | NO | NO |
CVE-2020-11965CRITICAL In IQrouter through 3.3.1, there is a root user without a password, which allows attackers to gain full remote access via SSH. Note: The vendor claims that this vulnerability can o | Apr 21, 2020 | 9.8 | 24 | NO | NO |
CVE-2020-11964HIGH In IQrouter through 3.3.1, the Lua function diag_set_password in the web-panel allows remote attackers to change the root password arbitrarily. Note: The vendor claims that this vu | Apr 21, 2020 | 7.5 | 20 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Evenroute.
Media articles that mention a CVE ID that affects a product developed by Evenroute — matched by CVE ID, not by vendor name.