Genexis manufactures a narrow range of residential and small-business gateway and access-point devices, most prominently the Platinum 4410, that despite limited product diversity sit within an actively monitored segment of network infrastructure. Vulnerabilities affecting the vendor skew strongly toward critical severity and frequently acquire public exploit code, with the recurring exposure centered on web-management interfaces and their handling of authentication, input validation, and sensitive data—including CSRF, cross-site scripting, OS command injection, and cleartext credential transmission. Defenders should prioritize inventory and patching of internet-accessible Genexis gateways; live exploitation status and severity breakdowns are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Genexis over time
Signals from CVEs in this vendor scope (8 CVEs).
8 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-29003CRITICAL Genexis PLATINUM 4410 2.1 P4410-V2-1.28 devices allow remote attackers to execute arbitrary code via shell metacharacters to sys_config_valid.xgi, as demonstrated by the sys_config | Apr 13, 2021 | 9.8 | 66 | NO | YES |
CVE-2020-6170CRITICAL An authentication bypass vulnerability on Genexis Platinum-4410 v2.1 P4410-V2 1.28 devices allows attackers to obtain cleartext credentials from the HTML source code of the cgi-bin | Jan 8, 2020 | 9.8 | 44 | NO | YES |
CVE-2020-25988MEDIUM UPNP Service listening on port 5555 in Genexis Platinum 4410 Router V2.1 (P4410-V2–1.34H) has an action 'X_GetAccess' which leaks the credentials of 'admin', provided that the atta | Nov 17, 2020 | 6.5 | 33 | NO | YES |
CVE-2020-25015MEDIUM A specific router allows changing the Wi-Fi password remotely. Genexis Platinum 4410 V2-1.28, a compact router generally used at homes and offices was found to be vulnerable to Bro | Sep 16, 2020 | 6.5 | 33 | NO | YES |
CVE-2017-6094CRITICAL CPEs used by subscribers on the access network receive their individual configuration settings from a central GAPS instance. A CPE identifies itself by the MAC address of its WAN i | Dec 20, 2017 | 9.8 | 31 | NO | NO |
CVE-2025-65883HIGH A vulnerability has been identified in Genexis Platinum P4410 router (Firmware P4410-V2–1.41) that allows a local network attacker to achieve Remote Code Execution (RCE) with root | Dec 4, 2025 | 8.4 | 24 | NO | NO |
CVE-2020-27980MEDIUM Genexis Platinum-4410 P4410-V2-1.28 devices allow stored XSS in the WLAN SSID parameter. This could allow an attacker to perform malicious actions in which the XSS popup will affec | Oct 28, 2020 | 5.4 | 20 | NO | NO |
CVE-2020-28137MEDIUM Cross site request forgery (CSRF) in Genexis Platinum 4410 V2-1.28, allows attackers to cause a denial of service by continuously restarting the router. | Nov 10, 2021 | 6.5 | 17 | NO | NO |
Signals from CVEs in this vendor scope (8 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Genexis.
Media articles that mention a CVE ID that affects a product developed by Genexis — matched by CVE ID, not by vendor name.