Inextrix's vulnerability footprint centers on its ASTPP (Wholesale Billing and Revenue Management) platform, a telecommunications and service-provider billing solution, with the durable signal concentrated in application-layer security issues. The recurring weakness classes—cross-site scripting, sensitive information exposure, hard-coded credentials, and weak cryptographic algorithms—reflect common security gaps in web-facing billing and administrative interfaces where configuration and authentication handling are critical. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Inextrix over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-37153CRITICAL ASTPP 4.0.1 contains multiple vulnerabilities including cross-site scripting and command injection in SIP device configuration and plugin management interfaces. Attackers can explo | Feb 11, 2026 | 9.8 | 32 | NO | NO |
CVE-2020-37104HIGH ASTPP 4.0.1 contains an information disclosure vulnerability that allows unauthenticated attackers to download database backup files by predicting backup filename patterns. Attacke | Feb 11, 2026 | 7.5 | 24 | NO | NO |
CVE-2019-15075HIGH An issue was discovered in iNextrix ASTPP before 4.0.1. web_interface/astpp/application/config/config.php does not have strong random keys, as demonstrated by use of the 8YSDaBtDHA | Mar 20, 2020 | 7.5 | 23 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Inextrix.
Media articles that mention a CVE ID that affects a product developed by Inextrix — matched by CVE ID, not by vendor name.