Financial Security Institute is a CNA that reports vulnerabilities affecting a narrow line of network security appliances and firmware, including models such as the FS010W, FS040U, and FS020W. The recurring exposure centers on web-interface weaknesses—cross-site request forgery, cross-site scripting, and insufficiently protected credentials—that are characteristic of embedded management interfaces. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Financial Security Institute (FSI) over time
Of all the CVEs published by Financial Security Institute (FSI) as a CNA, 0.0% affect products that Financial Security Institute (FSI) develops as a vendor.
Of all the CVEs published that affect products developed by Financial Security Institute (FSI), 0.0% are self-published by Financial Security Institute (FSI) as a CNA.
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-0520HIGH Cross-site request forgery (CSRF) vulnerability in FS010W firmware FS010W_00_V1.3.0 and earlier allows an attacker to hijack the authentication of administrators via unspecified ve | Feb 23, 2018 | 8.8 | 26 | NO | NO |
CVE-2022-43470HIGH Cross-site request forgery (CSRF) vulnerability in +F FS040U software versions v2.3.4 and earlier, +F FS020W software versions v4.0.0 and earlier, +F FS030W software versions v3.3. | Dec 5, 2022 | 7.3 | 23 | NO | NO |
CVE-2022-43442MEDIUM Plaintext storage of a password vulnerability exists in +F FS040U software versions v2.3.4 and earlier, which may allow an attacker to obtain the login password of +F FS040U and lo | Dec 5, 2022 | 4.6 | 19 | NO | NO |
CVE-2018-0519MEDIUM Cross-site scripting vulnerability in FS010W firmware FS010W_00_V1.3.0 and earlier allows an attacker to inject arbitrary web script or HTML via unspecified vectors. | Feb 23, 2018 | 4.8 | 18 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Financial Security Institute (FSI).
Media articles that mention a CVE ID that affects a product developed by Financial Security Institute (FSI) — matched by CVE ID, not by vendor name.