Fantec's vulnerability footprint is concentrated in its MWID25-DS network storage device and its firmware, with observed weaknesses centered on session-handling deficiencies including insecure cookie validation and session fixation. Treat this as a niche vendor profile; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Fantec over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-28113HIGH An issue in upload.csp of FANTEC GmbH MWiD25-DS Firmware v2.000.030 allows attackers to write files and reset the user passwords without having a valid session cookie. | Apr 15, 2022 | 7.2 | 25 | NO | NO |
CVE-2022-26591HIGH FANTEC GmbH MWiD25-DS Firmware v2.000.030 allows unauthenticated attackers to access and download arbitrary files via a crafted GET request. | Apr 6, 2022 | 7.5 | 25 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Fantec.
Media articles that mention a CVE ID that affects a product developed by Fantec — matched by CVE ID, not by vendor name.