F Logic's vulnerability profile centers on a narrow product line of datacube appliances and their embedded firmware, which occupy a specialized niche in the vulnerability landscape despite their prominence within that segment. The observed disclosures reflect the firmware and embedded-systems context of these devices. Live severity, exploitation, and current exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by F Logic over time
Signals from CVEs in this vendor scope (9 CVEs).
9 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-25830CRITICAL F-logic DataCube3 v1.0 is vulnerable to Incorrect Access Control due to an improper directory access restriction. An unauthenticated, remote attacker can exploit this, by sending a | Feb 29, 2024 | 9.8 | 52 | NO | YES |
CVE-2024-31750CRITICAL SQL injection vulnerability in f-logic datacube3 v.1.0 allows a remote attacker to obtain sensitive information via the req_id parameter. | Apr 19, 2024 | 9.8 | 44 | NO | YES |
CVE-2024-25832HIGH F-logic DataCube3 v1.0 is vulnerable to unrestricted file upload, which could allow an authenticated malicious actor to upload a file of dangerous type by manipulating the filename | Feb 29, 2024 | 8.8 | 43 | NO | YES |
CVE-2024-34854CRITICAL F-logic DataCube3 v1.0 is vulnerable to File Upload via `/admin/transceiver_schedule.php.` | May 28, 2024 | 9.8 | 32 | NO | NO |
CVE-2024-7066CRITICAL A vulnerability was found in F-logic DataCube3 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /admin/config_time_sync | Jul 24, 2024 | 9.8 | 30 | NO | NO |
CVE-2024-25833CRITICAL F-logic DataCube3 v1.0 is vulnerable to unauthenticated SQL injection, which could allow an unauthenticated malicious actor to execute arbitrary SQL queries in database. | Feb 29, 2024 | 9.8 | 28 | NO | NO |
CVE-2023-5329HIGH A vulnerability classified as problematic was found in Field Logic DataCube4 up to 20231001. This vulnerability affects unknown code of the file /api/ of the component Web API. The | Oct 2, 2023 | 7.5 | 22 | NO | NO |
CVE-2024-34852MEDIUM F-logic DataCube3 v1.0 is affected by command injection due to improper string filtering at the command execution point in the ./admin/transceiver_schedule.php file. An unauthentic | May 28, 2024 | 6.3 | 20 | NO | NO |
CVE-2024-25831MEDIUM F-logic DataCube3 Version 1.0 is affected by a reflected cross-site scripting (XSS) vulnerability due to improper input sanitization. An authenticated, remote attacker can execute | Feb 29, 2024 | 5.4 | 18 | NO | NO |
Signals from CVEs in this vendor scope (9 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by F Logic.
Media articles that mention a CVE ID that affects a product developed by F Logic — matched by CVE ID, not by vendor name.