Filewave develops mobile device management software whose vulnerability footprint centers on a single product line, with the durable signal focused on credential-handling practices. The recurring exposure involves hard-coded credentials embedded in the software, a structural weakness that can grant unauthorized access to managed devices or administrative interfaces. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Filewave over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-34907CRITICAL An authentication bypass vulnerability exists in FileWave before 14.6.3 and 14.7.x before 14.7.2. Exploitation could allow an unauthenticated actor to gain access to the system wit | Jul 25, 2022 | 9.8 | 39 | NO | NO |
CVE-2022-34906HIGH A hard-coded cryptographic key is used in FileWave before 14.6.3 and 14.7.x before 14.7.2. Exploitation could allow an unauthenticated actor to decrypt sensitive information saved | Jul 25, 2022 | 7.5 | 29 | NO | NO |
CVE-2025-43922HIGH The FileWave Windows client before 16.0.0, in some non-default configurations, allows an unprivileged local user to escalate privileges to SYSTEM. | Apr 21, 2025 | 8.1 | 24 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Filewave.
Media articles that mention a CVE ID that affects a product developed by Filewave — matched by CVE ID, not by vendor name.