Generex operates in the industrial control and remote-access space with a focused product line centered on devices such as the CS141 and associated firmware, commands, and management tooling that serve niche but critical infrastructure segments. Vulnerabilities affecting this vendor skew strongly toward critical-severity outcomes and recur across input-handling and file-access boundaries, including improper input validation, unrestricted file uploads, path traversal, and symlink-following conditions that are typical of firmware and embedded management interfaces where input constraints and filesystem isolation are often incomplete. Defenders should prioritize inventory and patching of affected devices given the severity profile; live exploitation status and current exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Generex over time
Signals from CVEs in this vendor scope (10 CVEs).
10 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-47190CRITICAL Generex UPS CS141 below 2.06 version, could allow a remote attacker to upload a firmware file containing a webshell that could allow him to execute arbitrary code as root. | Mar 31, 2023 | 9.8 | 30 | NO | NO |
CVE-2022-47192HIGH Generex UPS CS141 below 2.06 version, could allow a remote attacker to upload a backup file containing a modified "users.json" to the web server of the device, allowing him to repl | Mar 31, 2023 | 8.8 | 27 | NO | NO |
CVE-2022-47191HIGH Generex UPS CS141 below 2.06 version, could allow a remote attacker to upload a firmware file containing a file with modified permissions, allowing him to escalate privileges. | Mar 31, 2023 | 8.8 | 27 | NO | NO |
CVE-2022-47189CRITICAL Generex UPS CS141 below 2.06 version, allows an attacker toupload a firmware file containing an incorrect configuration, in order to disrupt the normal functionality of the device. | Mar 31, 2023 | 9.1 | 27 | NO | NO |
CVE-2022-47186CRITICAL There is an unrestricted upload of file vulnerability in Generex CS141 below 2.06 version. An attacker could upload and/or delete any type of file, without any format restriction a | Sep 28, 2023 | 9.1 | 26 | NO | NO |
CVE-2022-47188HIGH There is an arbitrary file reading vulnerability in Generex UPS CS141 below 2.06 version. An attacker, making use of the default credentials, could upload a backup file containing | Mar 31, 2023 | 7.5 | 23 | NO | NO |
CVE-2022-26041MEDIUM Directory traversal vulnerability in RCCMD 4.26 and earlier allows a remote authenticated attacker with an administrative privilege to read or alter an arbitrary file on the server | Jun 13, 2022 | 6.5 | 23 | NO | NO |
CVE-2020-11420MEDIUM UPS Adapter CS141 before 1.90 allows Directory Traversal. An attacker with Admin or Engineer login credentials could exploit the vulnerability by manipulating variables that refere | Apr 27, 2020 | 6.5 | 22 | NO | NO |
CVE-2022-42457HIGH Generex CS141 through 2.10 allows remote command execution by administrators via a web interface that reaches run_update in /usr/bin/gxserve-update.sh (e.g., command execution can | Oct 6, 2022 | 7.2 | 19 | NO | NO |
CVE-2022-47187MEDIUM There is a file upload XSS vulnerability in Generex CS141 below 2.06 version. The web application allows file uploading, making it possible to upload a file with HTML content. When | Sep 28, 2023 | 6.1 | 17 | NO | NO |
Signals from CVEs in this vendor scope (10 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Generex.
Media articles that mention a CVE ID that affects a product developed by Generex — matched by CVE ID, not by vendor name.