Invoxia's vulnerability footprint centers on its NVX220 network appliance and associated firmware, with the observed exposure clustering around authentication and information-disclosure weaknesses such as hard-coded credentials and exposure of sensitive data to unauthorized actors. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Invoxia over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-14528CRITICAL Invoxia NVX220 devices allow TELNET access as admin with a default password. | Jul 5, 2019 | 9.8 | 29 | NO | NO |
CVE-2018-14529HIGH Invoxia NVX220 devices allow access to /bin/sh via escape from a restricted CLI, leading to disclosure of password hashes. | Jul 5, 2019 | 7.5 | 23 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Invoxia.
Media articles that mention a CVE ID that affects a product developed by Invoxia — matched by CVE ID, not by vendor name.