I Drive operates a narrow product line centered on embedded storage and firmware components including the i11, i12, and Filo product families. The observed vulnerabilities reflect input-handling and validation concerns typical of embedded systems with limited attack-surface exposure relative to internet-facing infrastructure. Current severity, exploitation, and exposure details are shown alongside this summary.
The number and severity of CVEs published that impact products developed by I Drive over time
Signals from CVEs in this vendor scope (14 CVEs).
14 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-34690CRITICAL iDrive RemotePC before 7.6.48 on Windows allows authentication bypass. A remote and unauthenticated attacker can bypass cloud authentication to connect and control a system via TCP | Jul 15, 2021 | 9.8 | 29 | NO | NO |
CVE-2000-0376HIGH Buffer overflow in the HTTP proxy server for the i-drive Filo software allows remote attackers to execute arbitrary commands via a long HTTP GET request. | Jun 7, 2000 | 10.0 | 25 | NO | NO |
CVE-2021-34692HIGH iDrive RemotePC before 7.6.48 on Windows allows privilege escalation. A local and low-privileged user can force RemotePC to execute an attacker-controlled executable with SYSTEM pr | Jul 15, 2021 | 7.8 | 24 | NO | NO |
CVE-2020-15351HIGH IDrive before 6.7.3.19 on Windows installs by default to %PROGRAMFILES(X86)%\IDriveWindows with weak folder permissions granting any user modify permission (i.e., NT AUTHORITY\Auth | Jun 26, 2020 | 7.8 | 24 | NO | NO |
CVE-2021-34691HIGH iDrive RemotePC before 4.0.1 on Linux allows denial of service. A remote and unauthenticated attacker can disconnect a valid user session by connecting to an ephemeral port. | Jul 15, 2021 | 7.5 | 23 | NO | NO |
CVE-2025-1879MEDIUM A vulnerability was found in i-Drive i11 and i12 up to 20250227 and classified as problematic. This issue affects some unknown processing of the component APK. The manipulation lea | Mar 3, 2025 | 6.8 | 21 | NO | NO |
CVE-2011-5290MEDIUM The SaveToFile method in the UniBasicPack.UniTextBox ActiveX control in UniBasic100_EDA1811C.ocx in IDrive Online Backup 3.4.0 allows remote attackers to write to arbitrary files v | Jan 1, 2015 | 6.4 | 21 | NO | NO |
CVE-2025-1882HIGH A vulnerability was found in i-Drive i11 and i12 up to 20250227. It has been rated as critical. Affected by this issue is some unknown functionality of the component Device Setting | Mar 3, 2025 | 7.0 | 20 | NO | NO |
CVE-2021-34689MEDIUM iDrive RemotePC before 7.6.48 on Windows allows information disclosure. A locally authenticated attacker can read the system's Personal Key in world-readable %PROGRAMDATA% log file | Jul 15, 2021 | 5.5 | 20 | NO | NO |
CVE-2021-34687MEDIUM iDrive RemotePC before 7.6.48 on Windows allows information disclosure. A man in the middle can recover a system's Personal Key when a client attempts to make a LAN connection. The | Jul 15, 2021 | 5.3 | 18 | NO | NO |
Signals from CVEs in this vendor scope (14 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by I Drive.
Media articles that mention a CVE ID that affects a product developed by I Drive — matched by CVE ID, not by vendor name.