Iodata manufactures a moderately broad line of network-attached storage and wireless networking devices, including its TS-WRLA and TS-WRLP product families, which occupy a prominent niche in small-business and edge-infrastructure deployments. Its vulnerability disclosures span a concentrated set of products and exhibit a meaningful share of serious-severity outcomes, with a moderate tendency toward public exploit availability. The recurring weakness classes—OS command injection, memory-buffer issues, cross-site scripting, and cross-site request forgery—reflect the embedded-device context and web-management interfaces common to network appliances, and indicate persistent input-validation and access-control challenges in firmware and administrative endpoints. Defenders deploying these devices should prioritize patching and restrict management access; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Iodata over time
Signals from CVEs in this vendor scope (36 CVEs).
36 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-19822HIGH A certain router administration interface (that includes Realtek APMIB 0.11f for Boa 0.94.14rc21) allows remote attackers to retrieve the configuration, including sensitive data (u | Jan 27, 2020 | 7.5 | 37 | NO | YES |
CVE-2023-29804HIGH WFS-SR03 v1.0.3 was discovered to contain a command injection vulnerability via the sys_smb_pwdmod function. | Apr 14, 2023 | 8.8 | 36 | NO | NO |
CVE-2019-19823HIGH A certain router administration interface (that includes Realtek APMIB 0.11f for Boa 0.94.14rc21) stores cleartext administrative passwords in flash memory and in a file. This affe | Jan 27, 2020 | 7.5 | 35 | NO | YES |
CVE-2023-29805CRITICAL WFS-SR03 v1.0.3 was discovered to contain a command injection vulnerability via the pro_stor_canceltrans_handler_part_19 function. | Apr 14, 2023 | 9.8 | 30 | NO | NO |
CVE-2016-4845HIGH Cross-site request forgery (CSRF) vulnerability on I-O DATA DEVICE HVL-A2.0, HVL-A3.0, HVL-A4.0, HVL-AT1.0S, HVL-AT2.0, HVL-AT3.0, HVL-AT4.0, HVL-AT2.0A, HVL-AT3.0A, and HVL-AT4.0A | Sep 24, 2016 | 8.8 | 29 | NO | NO |
CVE-2018-0663HIGH Multiple I-O DATA network camera products (TS-WRLP firmware Ver.1.09.04 and earlier, TS-WRLA firmware Ver.1.09.04 and earlier, TS-WRLP/E firmware Ver.1.09.04 and earlier) use hardc | Sep 7, 2018 | 8.8 | 28 | NO | NO |
CVE-2017-2223HIGH Cross-site request forgery (CSRF) vulnerability in TS-WPTCAM, TS-PTCAM, TS-PTCAM/POE, TS-WLC2, TS-WLCE, TS-WRLC firmware version 1.19 and earlier and TS-WPTCAM2 firmware version 1. | Jul 7, 2017 | 8.8 | 28 | NO | NO |
CVE-2016-7806CRITICAL I-O DATA DEVICE WFS-SR01 firmware version 1.10 and earlier allow remote attackers to execute arbitrary OS commands via unspecified vectors. | Jun 9, 2017 | 9.8 | 28 | NO | NO |
CVE-2018-0661HIGH Multiple I-O DATA network camera products (TS-WRLP firmware Ver.1.09.04 and earlier, TS-WRLA firmware Ver.1.09.04 and earlier, TS-WRLP/E firmware Ver.1.09.04 and earlier) allow an | Sep 7, 2018 | 8.8 | 27 | NO | NO |
CVE-2016-4820HIGH Cross-site request forgery (CSRF) vulnerability on I-O DATA DEVICE ETX-R devices allows remote attackers to hijack the authentication of arbitrary users. | Jun 19, 2016 | 8.8 | 27 | NO | NO |
Signals from CVEs in this vendor scope (36 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Iodata.
Media articles that mention a CVE ID that affects a product developed by Iodata — matched by CVE ID, not by vendor name.