Farsite's vulnerability profile centers on the Farlinx X.25 Gateway and its firmware, specialized telecommunications and network-access appliances that handle protocol translation and remote connectivity. The observed weakness classes—path traversal, OS command injection, and out-of-bounds writes—reflect the parser complexity and privilege-bearing operations inherent to gateway firmware, particularly where input validation and memory safety matter in a device that bridges external networks. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Farsite over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2014-7173CRITICAL FarLinX X25 Gateway through 2014-09-25 allows command injection via shell metacharacters to sysSaveMonitorData.php, fsx25MonProxy.php, syseditdate.php, iframeupload.php, or sysRest | Jun 1, 2020 | 9.8 | 25 | NO | NO |
CVE-2014-7175CRITICAL FarLinX X25 Gateway through 2014-09-25 allows attackers to write arbitrary data to fsUI.xyz via fsSaveUIPersistence.php. | Jun 1, 2020 | 9.8 | 24 | NO | NO |
CVE-2014-7174MEDIUM FarLinX X25 Gateway through 2014-09-25 allows directory traversal via the log-handling feature. | Jun 1, 2020 | 5.3 | 16 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Farsite.
Media articles that mention a CVE ID that affects a product developed by Farsite — matched by CVE ID, not by vendor name.