Gatesair develops a focused line of broadcast-transmission and radiofrequency products, including the Flexiva series of FM transmitters and associated firmware, where disclosed vulnerabilities center on information exposure, cross-site scripting in web interfaces, and credential-handling weaknesses. These recurring patterns reflect the embedded and networked nature of broadcast equipment and the exposure risk inherent in accessible management interfaces. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Gatesair over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-36082CRITICAL An isssue in GatesAIr Flexiva FM Transmitter/Exiter Fax 150W allows a remote attacker to gain privileges via the LDAP and SMTP credentials. | Aug 3, 2023 | 9.8 | 28 | NO | NO |
CVE-2025-63212MEDIUM GatesAir Flexiva-LX devices on firmware 1.0.13 and 2.0, including models LX100, LX300, LX600, and LX1000, expose sensitive session identifiers (sid) in the publicly accessible log | Nov 19, 2025 | 6.5 | 22 | NO | NO |
CVE-2023-36081MEDIUM Cross Site Scripting vulnerability in GatesAIr Flexiva FM Transmitter/Exciter v.FAX 150W allows a remote attacker to execute arbitrary code via a crafted script to the web applicat | Aug 2, 2023 | 5.4 | 19 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Gatesair.
Media articles that mention a CVE ID that affects a product developed by Gatesair — matched by CVE ID, not by vendor name.