Greenpacket develops a narrow line of network appliance products, notably the DX-350 and DV-360 device families, that function as WAN accelerators and optimization gateways deployed in enterprise network infrastructure. Vulnerabilities affecting this vendor skew strongly toward critical-severity outcomes and cluster around command injection, cross-site request forgery, hard-coded credentials, and missing authentication controls—a pattern typical of embedded appliances where administrative interfaces and system-level commands are exposed through web frontends or API handlers with insufficient input validation and access controls. Defenders should prioritize inventory and patching of these appliances, particularly internet-reachable instances; live severity and exploitation counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Greenpacket over time
Signals from CVEs in this vendor scope (8 CVEs).
8 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-14067CRITICAL Green Packet WiMax DV-360 2.10.14-g1.0.6.1 devices allow Command Injection, with unauthenticated remote command execution, via a crafted payload to the HTTPS port, because lighttpd | Dec 31, 2020 | 9.8 | 32 | NO | NO |
CVE-2016-6552CRITICAL Green Packet DX-350 uses non-random default credentials of: root:wimax. A remote network attacker can gain privileged access to a vulnerable device. | Jul 13, 2018 | 9.8 | 31 | NO | NO |
CVE-2023-26866CRITICAL GreenPacket OH736's WR-1200 Indoor Unit, OT-235 with firmware versions M-IDU-1.6.0.3_V1.1 and MH-46360-2.0.3-R5-GP respectively are vulnerable to remote command injection. Commands | Apr 4, 2023 | 9.8 | 30 | NO | NO |
CVE-2017-9980CRITICAL In Green Packet DX-350 Firmware version v2.8.9.5-g1.4.8-atheeb, the "PING" (aka tag_ipPing) feature within the web interface allows performing command injection, via the "pip" para | Jul 21, 2017 | 9.8 | 30 | NO | NO |
CVE-2017-9932CRITICAL Green Packet DX-350 Firmware version v2.8.9.5-g1.4.8-atheeb has a default password of admin for the admin account. | Jul 21, 2017 | 9.8 | 29 | NO | NO |
CVE-2017-9930HIGH Cross-Site Request Forgery (CSRF) exists in Green Packet DX-350 Firmware version v2.8.9.5-g1.4.8-atheeb, as demonstrated by a request to ajax.cgi that enables UPnP. | Jul 21, 2017 | 8.8 | 27 | NO | NO |
CVE-2017-3216CRITICAL WiMAX routers based on the MediaTek SDK (libmtk) that use a custom httpd plugin are vulnerable to an authentication bypass allowing a remote, unauthenticated attacker to gain admin | Jun 20, 2017 | 9.8 | 26 | NO | NO |
CVE-2017-9931MEDIUM Cross-Site Scripting (XSS) exists in Green Packet DX-350 Firmware version v2.8.9.5-g1.4.8-atheeb, as demonstrated by the action parameter to ajax.cgi. | Jul 21, 2017 | 6.1 | 21 | NO | NO |
Signals from CVEs in this vendor scope (8 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Greenpacket.
Media articles that mention a CVE ID that affects a product developed by Greenpacket — matched by CVE ID, not by vendor name.