Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Generex

First CVE: Apr 27, 2020Active for: 6 yearsTotal CVEs: 10
38.6
VTI Score
Medium

Generex operates in the industrial control and remote-access space with a focused product line centered on devices such as the CS141 and associated firmware, commands, and management tooling that serve niche but critical infrastructure segments. Vulnerabilities affecting this vendor skew strongly toward critical-severity outcomes and recur across input-handling and file-access boundaries, including improper input validation, unrestricted file uploads, path traversal, and symlink-following conditions that are typical of firmware and embedded management interfaces where input constraints and filesystem isolation are often incomplete. Defenders should prioritize inventory and patching of affected devices given the severity profile; live exploitation status and current exposure counts are shown alongside this summary.

FAUCET AI Generated
10
Total CVEs
More Total CVEs than 92% of tracked vendors
1.1
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 74% of tracked vendors
7.9
Avg CVSS Score
Higher Avg CVSS Score than 77% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Generex over time

Volume of CVEsAvg CVSS Base Score
First CVE
Apr 27, 2020
6 years ago
Most Recent CVE
Sep 28, 2023
1,030 days ago

Products(3 total)

Top CVEs

Signals from CVEs in this vendor scope (10 CVEs).

10 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2022-47190CRITICAL
Generex UPS CS141 below 2.06 version, could allow a remote attacker to upload a firmware file containing a webshell that could allow him to execute arbitrary code as root.
Mar 31, 20239.830NONO
CVE-2022-47192HIGH
Generex UPS CS141 below 2.06 version, could allow a remote attacker to upload a backup file containing a modified "users.json" to the web server of the device, allowing him to repl
Mar 31, 20238.827NONO
CVE-2022-47191HIGH
Generex UPS CS141 below 2.06 version, could allow a remote attacker to upload a firmware file containing a file with modified permissions, allowing him to escalate privileges.
Mar 31, 20238.827NONO
CVE-2022-47189CRITICAL
Generex UPS CS141 below 2.06 version, allows an attacker toupload a firmware file containing an incorrect configuration, in order to disrupt the normal functionality of the device.
Mar 31, 20239.127NONO
CVE-2022-47186CRITICAL
There is an unrestricted upload of file vulnerability in Generex CS141 below 2.06 version. An attacker could upload and/or delete any type of file, without any format restriction a
Sep 28, 20239.126NONO
CVE-2022-47188HIGH
There is an arbitrary file reading vulnerability in Generex UPS CS141 below 2.06 version. An attacker, making use of the default credentials, could upload a backup file containing
Mar 31, 20237.523NONO
CVE-2022-26041MEDIUM
Directory traversal vulnerability in RCCMD 4.26 and earlier allows a remote authenticated attacker with an administrative privilege to read or alter an arbitrary file on the server
Jun 13, 20226.523NONO
CVE-2020-11420MEDIUM
UPS Adapter CS141 before 1.90 allows Directory Traversal. An attacker with Admin or Engineer login credentials could exploit the vulnerability by manipulating variables that refere
Apr 27, 20206.522NONO
CVE-2022-42457HIGH
Generex CS141 through 2.10 allows remote command execution by administrators via a web interface that reaches run_update in /usr/bin/gxserve-update.sh (e.g., command execution can
Oct 6, 20227.219NONO
CVE-2022-47187MEDIUM
There is a file upload XSS vulnerability in Generex CS141 below 2.06 version. The web application allows file uploading, making it possible to upload a file with HTML content. When
Sep 28, 20236.117NONO
View all 10 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products10 CVEs
30%
40%
30%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network10 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low10 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None9 (90.0%)
Unknown0 (0.0%)
Required1 (10.0%)
Privileges Required
Low3 (30.0%)
High2 (20.0%)
None5 (50.0%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (10 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Generex.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Generex — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Generex's Products

View all 3 CNAs →

Top CWEs