Fanuc manufactures industrial robotics control systems and simulation software widely deployed across manufacturing environments, with a concentrated vulnerability footprint spanning its RoboGuide simulation suite and R-30 series controller firmware. The observed weakness classes—path traversal, uncontrolled resource consumption, improper access control, XML external entity injection, and numeric conversion errors—reflect the complexity of embedded control interfaces and file-handling logic in industrial automation platforms. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Fanuc over time
Signals from CVEs in this vendor scope (9 CVEs).
9 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-1864HIGH FANUC ROBOGUIDE-HandlingPRO Versions 9 Rev.ZD and prior is vulnerable to
a path traversal, which could allow an attacker to remotely read files
on the system running the affected | Jun 7, 2023 | 7.5 | 24 | NO | NO |
CVE-2021-32998HIGH The FANUC R-30iA and R-30iB series controllers are vulnerable to an out-of-bounds write, which may allow an attacker to remotely execute arbitrary code. INIT START/restore from bac | Jan 10, 2022 | 7.4 | 24 | NO | NO |
CVE-2021-32996HIGH The FANUC R-30iA and R-30iB series controllers are vulnerable to integer coercion errors, which cause the device to crash. A restart is required. | Jan 10, 2022 | 7.5 | 24 | NO | NO |
CVE-2021-43986HIGH The setup program for the affected product configures its files and folders with full access, which may allow unauthorized users permission to replace original binaries and achieve | Apr 20, 2022 | 7.0 | 23 | NO | NO |
CVE-2021-43933MEDIUM The affected product is vulnerable to a network-based attack by threat actors sending unimpeded requests to the receiving server, which could cause a denial-of-service condition du | Apr 20, 2022 | 5.9 | 21 | NO | NO |
CVE-2021-38483MEDIUM The affected product is vulnerable to misconfigured binaries, allowing users on the target PC with SYSTEM level privileges access to overwrite the binary and modify files to gain p | Apr 20, 2022 | 5.7 | 21 | NO | NO |
CVE-2021-43990MEDIUM The affected product is vulnerable to a network-based attack by threat actors supplying a crafted, malicious XML payload designed to trigger an external entity reference call. | Apr 20, 2022 | 5.3 | 20 | NO | NO |
CVE-2021-43988MEDIUM The affected product is vulnerable to a network-based attack by threat actors utilizing crafted naming conventions of files to gain unauthorized access rights. | Apr 20, 2022 | 5.9 | 16 | NO | NO |
CVE-2020-12739MEDIUM A denial-of-service vulnerability in the Fanuc i Series CNC (0i-MD and 0i Mate-MD) could allow an unauthenticated, remote attacker to cause an affected CNC to become inaccessible t | Aug 3, 2020 | 5.3 | 16 | NO | NO |
Signals from CVEs in this vendor scope (9 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Fanuc.
Media articles that mention a CVE ID that affects a product developed by Fanuc — matched by CVE ID, not by vendor name.