Hot maintains a narrowly scoped portfolio centered on the HotBox router and its firmware, which despite limited product breadth carries notable internet-facing exposure as a networking appliance. The vendor's vulnerability profile recurs through web-application and access-control weakness classes including cross-site request forgery, improper authentication, input validation flaws, path traversal, and cross-site scripting—patterns characteristic of embedded web interfaces with insufficient input sanitization and session protection. Live severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Hot over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2013-5038MEDIUM The HOT HOTBOX router with software 2.1.11 allows remote attackers to bypass authentication by configuring a source IP address that had previously been used for an authenticated se | Dec 30, 2013 | 5.8 | 30 | NO | YES |
CVE-2013-5220MEDIUM goform/login on the HOT HOTBOX router with software 2.1.11 allows remote attackers to cause a denial of service (device crash) via crafted HTTP POST data. | Dec 30, 2013 | 6.1 | 26 | NO | YES |
The HOT HOTBOX router with software 2.1.11 has a default WPS PIN of 12345670, which makes it easier for remote attackers to obtain the WPA or WPA2 pre-shared key via EAP messages. | Dec 30, 2013 | 3.3 | 24 | NO | YES |
CVE-2013-5039MEDIUM Cross-site request forgery (CSRF) vulnerability in goform/wlanBasicSecurity on the HOT HOTBOX router with software 2.1.11 allows remote attackers to hijack the authentication of ad | Dec 30, 2013 | 5.4 | 23 | NO | YES |
Directory traversal vulnerability on the HOT HOTBOX router with software 2.1.11 allows remote attackers to read arbitrary files via a .. (dot dot) in a URI, as demonstrated by a re | Dec 30, 2013 | 3.3 | 20 | NO | YES |
Cross-site scripting (XSS) vulnerability on the HOT HOTBOX router with software 2.1.11 allows remote attackers to inject arbitrary web script or HTML via a crafted DHCP Host Name o | Dec 30, 2013 | 2.9 | 19 | NO | YES |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Hot.
Media articles that mention a CVE ID that affects a product developed by Hot — matched by CVE ID, not by vendor name.