Gryphonconnect's vulnerability footprint centers on its Gryphon Tower network security and content-filtering appliance, a specialized device deployed in corporate and educational environments. The recurring weakness classes—including OS command injection, improper authentication, cross-site scripting, and insufficiently protected credentials—reflect the device's dual exposure as both a command-line and web-administered system handling privileged network control. A moderate share of vulnerabilities reach serious severity and tend to acquire public exploit code, underscoring the risk that an unpatched appliance presents to the networks it is meant to protect. Defenders should prioritize updates for this vendor's edge-deployed products; current severity and exploitation activity are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Gryphonconnect over time
Signals from CVEs in this vendor scope (10 CVEs).
10 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-20137MEDIUM A reflected cross-site scripting vulnerability exists in the url parameter of the /cgi-bin/luci/site_access/ page on the Gryphon Tower router's web interface. An attacker could exp | Dec 9, 2021 | 6.1 | 32 | NO | YES |
CVE-2021-20146CRITICAL An unprotected ssh private key exists on the Gryphon devices which could be used to achieve root access to a server affiliated with Gryphon's development and infrastructure. At the | Dec 9, 2021 | 9.8 | 31 | NO | NO |
CVE-2021-20144HIGH An unauthenticated command injection vulnerability exists in the parameters of operation 49 in the controller_server service on Gryphon Tower routers. An unauthenticated remote att | Dec 9, 2021 | 8.8 | 29 | NO | NO |
CVE-2021-20143HIGH An unauthenticated command injection vulnerability exists in the parameters of operation 48 in the controller_server service on Gryphon Tower routers. An unauthenticated remote att | Dec 9, 2021 | 8.8 | 29 | NO | NO |
CVE-2021-20142HIGH An unauthenticated command injection vulnerability exists in the parameters of operation 41 in the controller_server service on Gryphon Tower routers. An unauthenticated remote att | Dec 9, 2021 | 8.8 | 29 | NO | NO |
CVE-2021-20141HIGH An unauthenticated command injection vulnerability exists in the parameters of operation 32 in the controller_server service on Gryphon Tower routers. An unauthenticated remote att | Dec 9, 2021 | 8.8 | 29 | NO | NO |
CVE-2021-20140HIGH An unauthenticated command injection vulnerability exists in the parameters of operation 10 in the controller_server service on Gryphon Tower routers. An unauthenticated remote att | Dec 9, 2021 | 8.8 | 29 | NO | NO |
CVE-2021-20139HIGH An unauthenticated command injection vulnerability exists in the parameters of operation 3 in the controller_server service on Gryphon Tower routers. An unauthenticated remote atta | Dec 9, 2021 | 8.8 | 29 | NO | NO |
CVE-2021-20138HIGH An unauthenticated command injection vulnerability exists in multiple parameters in the Gryphon Tower router’s web interface at /cgi-bin/luci/rc. An unauthenticated remote attacker | Dec 9, 2021 | 8.8 | 29 | NO | NO |
CVE-2021-20145HIGH Gryphon Tower routers contain an unprotected openvpn configuration file which can grant attackers access to the Gryphon homebound VPN network which exposes the LAN interfaces of ot | Dec 9, 2021 | 7.5 | 25 | NO | NO |
Signals from CVEs in this vendor scope (10 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Gryphonconnect.
Media articles that mention a CVE ID that affects a product developed by Gryphonconnect — matched by CVE ID, not by vendor name.