Hillstonenet develops a focused line of network security appliances centered on its SC-6000 firewall and threat-prevention platform, with vulnerabilities clustering around input handling and access-control weaknesses. The recurring weakness classes—improper access control, input validation flaws, cross-site scripting, and command injection—reflect the challenges of web-facing and command-processing components common to security appliances; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Hillstonenet over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-8073CRITICAL Improper Input Validation vulnerability in Hillstone Networks Hillstone Networks Web Application Firewall on 5.5R6 allows Command Injection.This issue affects Hillstone Networks We | Aug 26, 2024 | 9.8 | 30 | NO | NO |
CVE-2022-45778CRITICAL https://www.hillstonenet.com.cn/ Hillstone Firewall SG-6000 <= 5.0.4.0 is vulnerable to Incorrect Access Control. There is a permission bypass vulnerability in the Hillstone WEB ap | Dec 27, 2022 | 9.8 | 29 | NO | NO |
CVE-2023-46964MEDIUM Cross Site Scripting (XSS) vulnerability in Hillstone Next Generation FireWall SG-6000-e3960 v.5.5 allows a remote attacker to execute arbitrary code via the use front-end filterin | Nov 5, 2023 | 6.1 | 19 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Hillstonenet.
Media articles that mention a CVE ID that affects a product developed by Hillstonenet — matched by CVE ID, not by vendor name.