Exemys develops a narrowly focused product line centered on the RME1 remote management engine and its associated firmware and telemetry infrastructure, components that sit in privileged positions within managed systems. The recurring vulnerability exposure reflects authentication and access-control deficiencies alongside information-disclosure pathways, typical of embedded management interfaces where sensitive operational data and control functions converge. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Exemys over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-2197CRITICAL By using a specific credential string, an attacker with network access to the device’s web interface could circumvent the authentication scheme and perform administrative operation | Jun 30, 2022 | 9.8 | 31 | NO | NO |
CVE-2015-7910HIGH Exemys Telemetry Web Server relies on an HTTP Location header to indicate that a client is unauthorized, which allows remote attackers to bypass intended access restrictions by dis | Nov 19, 2015 | 7.8 | 27 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Exemys.
Media articles that mention a CVE ID that affects a product developed by Exemys — matched by CVE ID, not by vendor name.