Ipcomm's vulnerability profile centers on its IPDIO product line and associated firmware, with the observed signal driven by application-layer injection and XSS weaknesses that are typical of web-facing device interfaces. Treat this as a compact vendor profile; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Ipcomm over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-22985HIGH The absence of filters when loading some sections in the web application of the vulnerable device allows attackers to inject malicious code that will be interpreted when a legitima | Mar 10, 2022 | 8.8 | 28 | NO | NO |
CVE-2022-24915HIGH The absence of filters when loading some sections in the web application of the vulnerable device allows attackers to inject malicious code that will be interpreted when a legitima | Mar 10, 2022 | 8.8 | 27 | NO | NO |
CVE-2022-21146MEDIUM Persistent cross-site scripting in the web interface of ipDIO allows an unauthenticated remote attacker to introduce arbitrary JavaScript by injecting an XSS payload into a specifi | Mar 10, 2022 | 6.1 | 21 | NO | NO |
CVE-2022-24432MEDIUM Persistent cross-site scripting (XSS) in the web interface of ipDIO allows an authenticated remote attacker to introduce arbitrary JavaScript by injecting an XSS payload into speci | Mar 10, 2022 | 5.4 | 19 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Ipcomm.
Media articles that mention a CVE ID that affects a product developed by Ipcomm — matched by CVE ID, not by vendor name.