Haascnc manufactures CNC controller hardware and firmware, with observed vulnerabilities concentrating in authentication and access-control handling: missing authentication for critical functions, insufficient granularity of access control, and cleartext transmission of sensitive information reflect the challenges of securing embedded industrial control systems. Treat this as a compact vendor profile rather than a broad trend line; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Haascnc over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-2475HIGH Haas Controller version 100.20.000.1110 has insufficient granularity of access control when using the "Ethernet Q Commands" service. Any user is able to write macros into registers | Oct 28, 2022 | 8.8 | 28 | NO | NO |
CVE-2022-2474HIGH Authentication is currently unsupported in Haas Controller version 100.20.000.1110 when using the “Ethernet Q Commands” service, which allows any user on the same network segment a | Oct 28, 2022 | 8.0 | 26 | NO | NO |
CVE-2022-41636HIGH Communication traffic involving "Ethernet Q Commands" service of Haas Controller version 100.20.000.1110 is transmitted in cleartext. This allows an attacker to obtain sensitive in | Oct 28, 2022 | 7.5 | 25 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Haascnc.
Media articles that mention a CVE ID that affects a product developed by Haascnc — matched by CVE ID, not by vendor name.