Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Eyesofnetwork

First CVE: Apr 11, 2017Active for: 9 yearsTotal CVEs: 40
69.4
VTI Score
TOP TARGET

Eyesofnetwork operates a monitoring and network-management platform with a narrow product footprint centered on its core web-facing interface, which serves as the administrative and operational hub for the system. Vulnerabilities affecting this vendor skew strongly toward critical-severity outcomes and frequently acquire public exploit tooling, concentrated in the web interface through a durable pattern of input-handling and command-injection flaws including SQL injection, cross-site scripting, OS command injection, and sensitive-information exposure. The attack surface is characterized by the direct accessibility of the web interface and the administrative privileges typically granted to it, making these weakness classes particularly high-risk in network environments. Defenders should treat Eyesofnetwork disclosures as requiring prompt inventory and patching of exposed instances, especially those reachable from untrusted networks. Current exploitation activity and exposure counts are shown alongside this summary.

FAUCET AI Generated
40
Total CVEs
More Total CVEs than 98% of tracked vendors
3.3
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 95% of tracked vendors
8.0
Avg CVSS Score
Higher Avg CVSS Score than 78% of tracked vendors
5.0%
In CISA KEV
Higher KEV Rate than 99% of tracked vendors

Trends Over Time

The number and severity of CVEs published that impact products developed by Eyesofnetwork over time

Volume of CVEsAvg CVSS Base Score
First CVE
Apr 11, 2017
9 years ago
Most Recent CVE
Jan 7, 2025
563 days ago

Products(2 total)

Top CVEs

Signals from CVEs in this vendor scope (40 CVEs).

40 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2020-8657CRITICAL
An issue was discovered in EyesOfNetwork 5.3. The installation uses the same API key (hardcoded as EONAPI_KEY in include/api_functions.php for API version 2.4.2) by default for all
Feb 6, 20209.898YESYES
CVE-2020-8655HIGH
An issue was discovered in EyesOfNetwork 5.3. The sudoers configuration is prone to a privilege escalation vulnerability, allowing the apache user to run arbitrary commands as root
Feb 7, 20207.894YESYES
CVE-2020-8656CRITICAL
An issue was discovered in EyesOfNetwork 5.3. The EyesOfNetwork API 2.4.2 is prone to SQL injection, allowing an unauthenticated attacker to perform various tasks such as authentic
Feb 7, 20209.892NOYES
CVE-2020-8654HIGH
An issue was discovered in EyesOfNetwork 5.3. An authenticated web user with sufficient privileges could abuse the AutoDiscovery module to run arbitrary OS commands via the /module
Feb 7, 20208.891NOYES
CVE-2020-9465CRITICAL
An issue was discovered in EyesOfNetwork eonweb 5.1 through 5.3 before 5.3-3. The eonweb web interface is prone to a SQL injection, allowing an unauthenticated attacker to perform
Feb 28, 20209.883NOYES
CVE-2021-27513HIGH
The module admin_ITSM in EyesOfNetwork 5.3-10 allows remote authenticated users to upload arbitrary .xml.php files because it relies on "le filtre userside."
Feb 22, 20218.841NONO
CVE-2017-6088HIGH
Multiple SQL injection vulnerabilities in EyesOfNetwork (aka EON) 5.0 and earlier allow remote authenticated users to execute arbitrary SQL commands via the (1) bp_name, (2) displa
Apr 11, 20177.237NOYES
CVE-2022-41570CRITICAL
An issue was discovered in EyesOfNetwork (EON) through 5.3.11. Unauthenticated SQL injection can occur.
Sep 27, 20229.832NONO
CVE-2021-40643CRITICAL
EyesOfNetwork before 07-07-2021 has a Remote Code Execution vulnerability on the mail options configuration page. In the location of the "sendmail" application in the "cacti" confi
Jun 30, 20229.831NONO
CVE-2017-1000060CRITICAL
EyesOfNetwork (EON) 5.1 Unauthenticated SQL Injection in eonweb leading to remote root
Jul 17, 20179.831NONO
View all 40 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products40 CVEs
25%
38%
38%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local1 (2.5%)
Network39 (97.5%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low40 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None29 (72.5%)
Unknown0 (0.0%)
Required11 (27.5%)
Privileges Required
Low11 (27.5%)
High9 (22.5%)
None20 (50.0%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (40 CVEs).

CISA KEV
2 CVEs
5.0% of CVEs· 99th percentile
Metasploit
5 CVEs
12.5% of CVEs· 98th percentile
Nuclei
3 CVEs
7.5% of CVEs· 96th percentile
ExploitDB
5 CVEs
12.5% of CVEs· 76th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Eyesofnetwork.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Eyesofnetwork — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Eyesofnetwork's Products

View all 1 CNAs →

Top CWEs