Impinj develops RFID reader hardware and firmware products designed for inventory and asset-tracking applications, a specialized industrial-IoT niche. The identified vulnerability patterns in its R420 reader center on web-interface input handling, with recurring weaknesses in cross-site scripting and open-redirect conditions typical of embedded management interfaces. Current severity, exploitation, and exposure figures are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Impinj over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-5303MEDIUM An issue was discovered on the Impinj Speedway Connect R420 RFID Reader before 2.2.2. The license key parameter of the web application is vulnerable to Cross Site Scripting; this v | May 11, 2018 | 5.4 | 19 | NO | NO |
CVE-2018-5304MEDIUM An issue was discovered on the Impinj Speedway Connect R420 RFID Reader before 2.2.2. The affected web interface is vulnerable to ClickJacking or UI Redressing: it is possible to a | May 11, 2018 | 4.3 | 17 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Impinj.
Media articles that mention a CVE ID that affects a product developed by Impinj — matched by CVE ID, not by vendor name.