Goldshell develops cryptocurrency mining hardware and associated firmware that sit at the intersection of embedded devices and financial infrastructure. The vendor's disclosed vulnerabilities cluster around credential and access-control weaknesses—cleartext storage of sensitive information, hard-coded credentials, and path-traversal issues—that are characteristic of firmware with minimal security hardening. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Goldshell over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-24657CRITICAL Goldshell ASIC Miners v2.1.x was discovered to contain hardcoded credentials which allow attackers to remotely connect via the SSH protocol (port 22). | Jul 20, 2022 | 9.8 | 30 | NO | NO |
CVE-2022-24659HIGH Goldshell ASIC Miners v2.2.1 and below was discovered to contain a path traversal vulnerability which allows unauthenticated attackers to retrieve arbitrary files from the device. | Jul 20, 2022 | 7.5 | 25 | NO | NO |
CVE-2022-24660HIGH The debug interface of Goldshell ASIC Miners v2.2.1 and below was discovered to be exposed publicly on the web interface, allowing attackers to access passwords and other sensitive | Jul 20, 2022 | 7.5 | 24 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Goldshell.
Media articles that mention a CVE ID that affects a product developed by Goldshell — matched by CVE ID, not by vendor name.