Hosteng's vulnerability footprint centers on a narrow line of e-commerce hardware appliances, particularly variants of the H0-ECOM100 platform and its firmware. The observed weaknesses—improper input validation, out-of-bounds writes, and stack-based buffer overflows—reflect the memory-safety and input-handling demands of embedded commerce devices. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Hosteng over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-3228MEDIUM Using custom code, an attacker can write into name or description fields larger than the appropriate buffer size causing a stack-based buffer overflow on Host Engineering H0-ECOM10 | Oct 28, 2022 | 6.5 | 22 | NO | NO |
CVE-2020-25195HIGH The length of the input fields of Host Engineering H0-ECOM100, H2-ECOM100, and H4-ECOM100 modules are verified only on the client side when receiving input from the configuration w | Dec 15, 2020 | 7.5 | 22 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Hosteng.
Media articles that mention a CVE ID that affects a product developed by Hosteng — matched by CVE ID, not by vendor name.