Genieacs is a narrowly scoped remote management platform for broadband customer premises equipment, with its vulnerability surface concentrated in a single product core. The observed weaknesses center on access-control and OS command-injection issues that are characteristic of management interfaces handling untrusted input from network endpoints. Current severity, exploitation status, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Genieacs over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-46704CRITICAL In GenieACS 1.2.x before 1.2.8, the UI interface API is vulnerable to unauthenticated OS command injection via the ping host argument (lib/ui/api.ts and lib/ping.ts). The vulnerabi | Mar 6, 2022 | 9.8 | 54 | NO | YES |
CVE-2025-56015HIGH In GenieACS 1.2.13, an unauthenticated access vulnerability exists in the NBI API endpoint. | Apr 7, 2026 | 7.5 | 27 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Genieacs.
Media articles that mention a CVE ID that affects a product developed by Genieacs — matched by CVE ID, not by vendor name.