Harmonicinc's vulnerability footprint concentrates on its NSG 9000 series of network security gateways and associated firmware, a narrowly scoped appliance line deployed in enterprise security infrastructure. The observed weakness classes—including sensitive information exposure, path traversal, missing authorization, and hard-coded credentials—reflect the authentication and access-control demands of edge-facing security appliances. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Harmonicinc over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-14943CRITICAL Harmonic NSG 9000 devices have a default password of nsgadmin for the admin account, a default password of nsgguest for the guest account, and a default password of nsgconfig for t | Aug 5, 2018 | 9.8 | 29 | NO | NO |
CVE-2018-14942HIGH Harmonic NSG 9000 devices allow remote authenticated users to conduct directory traversal attacks, as demonstrated by "POST /PY/EMULATION_GET_FILE" or "POST /PY/EMULATION_EXPORT" w | Aug 5, 2018 | 8.8 | 26 | NO | NO |
CVE-2018-14941MEDIUM Harmonic NSG 9000 devices allow remote authenticated users to read the webapp.py source code via a direct request for the /webapp.py URI. | Aug 5, 2018 | 6.5 | 21 | NO | NO |
CVE-2023-33477MEDIUM In Harmonic NSG 9000-6G devices, an authenticated remote user can obtain source code by directly requesting a special path. | Jun 6, 2023 | 6.5 | 20 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Harmonicinc.
Media articles that mention a CVE ID that affects a product developed by Harmonicinc — matched by CVE ID, not by vendor name.