I O Data manufactures a line of network-attached storage and file server appliances, with vulnerability disclosures clustering around its HLF series products. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by I O Data over time
Signals from CVEs in this vendor scope (36 CVEs).
36 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-19822HIGH A certain router administration interface (that includes Realtek APMIB 0.11f for Boa 0.94.14rc21) allows remote attackers to retrieve the configuration, including sensitive data (u | Jan 27, 2020 | 7.5 | 37 | NO | YES |
CVE-2023-29804HIGH WFS-SR03 v1.0.3 was discovered to contain a command injection vulnerability via the sys_smb_pwdmod function. | Apr 14, 2023 | 8.8 | 36 | NO | NO |
CVE-2019-19823HIGH A certain router administration interface (that includes Realtek APMIB 0.11f for Boa 0.94.14rc21) stores cleartext administrative passwords in flash memory and in a file. This affe | Jan 27, 2020 | 7.5 | 35 | NO | YES |
CVE-2023-29805CRITICAL WFS-SR03 v1.0.3 was discovered to contain a command injection vulnerability via the pro_stor_canceltrans_handler_part_19 function. | Apr 14, 2023 | 9.8 | 30 | NO | NO |
CVE-2016-4845HIGH Cross-site request forgery (CSRF) vulnerability on I-O DATA DEVICE HVL-A2.0, HVL-A3.0, HVL-A4.0, HVL-AT1.0S, HVL-AT2.0, HVL-AT3.0, HVL-AT4.0, HVL-AT2.0A, HVL-AT3.0A, and HVL-AT4.0A | Sep 24, 2016 | 8.8 | 29 | NO | NO |
CVE-2018-0663HIGH Multiple I-O DATA network camera products (TS-WRLP firmware Ver.1.09.04 and earlier, TS-WRLA firmware Ver.1.09.04 and earlier, TS-WRLP/E firmware Ver.1.09.04 and earlier) use hardc | Sep 7, 2018 | 8.8 | 28 | NO | NO |
CVE-2017-2223HIGH Cross-site request forgery (CSRF) vulnerability in TS-WPTCAM, TS-PTCAM, TS-PTCAM/POE, TS-WLC2, TS-WLCE, TS-WRLC firmware version 1.19 and earlier and TS-WPTCAM2 firmware version 1. | Jul 7, 2017 | 8.8 | 28 | NO | NO |
CVE-2016-7806CRITICAL I-O DATA DEVICE WFS-SR01 firmware version 1.10 and earlier allow remote attackers to execute arbitrary OS commands via unspecified vectors. | Jun 9, 2017 | 9.8 | 28 | NO | NO |
CVE-2018-0661HIGH Multiple I-O DATA network camera products (TS-WRLP firmware Ver.1.09.04 and earlier, TS-WRLA firmware Ver.1.09.04 and earlier, TS-WRLP/E firmware Ver.1.09.04 and earlier) allow an | Sep 7, 2018 | 8.8 | 27 | NO | NO |
CVE-2016-4820HIGH Cross-site request forgery (CSRF) vulnerability on I-O DATA DEVICE ETX-R devices allows remote attackers to hijack the authentication of arbitrary users. | Jun 19, 2016 | 8.8 | 27 | NO | NO |
Signals from CVEs in this vendor scope (36 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by I O Data.
Media articles that mention a CVE ID that affects a product developed by I O Data — matched by CVE ID, not by vendor name.