Gurux develops the Device Language Message Specification Director, a narrowly scoped tool for device communication and protocol specification, with observed vulnerabilities clustering around code-integrity and path-traversal issues. The vendor's exposure centers on unsafe handling of downloaded code and insufficient pathname validation, which are structural risks in software that processes external specifications and device configurations; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Gurux over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-8809HIGH Gurux GXDLMS Director prior to 8.5.1905.1301 downloads updates to add-ins and OBIS code over an unencrypted HTTP connection. A man-in-the-middle attacker can prompt the user to dow | Feb 25, 2020 | 8.1 | 26 | NO | NO |
CVE-2020-8810HIGH An issue was discovered in Gurux GXDLMS Director through 8.5.1905.1301. When downloading OBIS codes, it does not verify that the downloaded files are actual OBIS codes and doesn't | Feb 25, 2020 | 8.1 | 24 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Gurux.
Media articles that mention a CVE ID that affects a product developed by Gurux — matched by CVE ID, not by vendor name.