Juplink's vulnerability profile centers on its RX4-1500 network appliance and firmware, a narrowly scoped but strategically positioned device for industrial and enterprise networking deployments. The recurring exposure reflects command-injection and OS-command-injection weaknesses alongside configuration and memory-safety issues endemic to embedded firmware, while vulnerabilities affecting the vendor skew toward serious outcomes. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Juplink over time
Signals from CVEs in this vendor scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-41028HIGH A stack-based buffer overflow exists in Juplink RX4-1500, a WiFi router, in versions 1.0.2 through 1.0.5. An authenticated attacker can exploit this vulnerability to achieve code e | Aug 23, 2023 | 8.8 | 28 | NO | NO |
CVE-2023-41030CRITICAL Hard-coded credentials in Juplink RX4-1500 versions V1.0.2 through V1.0.5 allow unauthenticated attackers to log in to the web interface or telnet service as the 'user' user. | Sep 18, 2023 | 9.8 | 27 | NO | NO |
CVE-2023-41029HIGH Command injection vulnerability in the homemng.htm endpoint in Juplink RX4-1500 Wifi router firmware versions V1.0.2, V1.0.3, V1.0.4, and V1.0.5 allows authenticated remote attacke | Sep 22, 2023 | 8.8 | 26 | NO | NO |
CVE-2023-41027HIGH Credential disclosure in the '/webs/userpasswd.htm' endpoint in Juplink RX4-1500 Wifi router firmware versions V1.0.4 and V1.0.5 allows an authenticated attacker to leak the passwo | Sep 22, 2023 | 8.8 | 26 | NO | NO |
CVE-2023-41031HIGH Command injection in homemng.htm in Juplink RX4-1500 versions V1.0.2, V1.0.3, V1.0.4, and V1.0.5 allows remote authenticated attackers to execute commands via specially crafted req | Sep 22, 2023 | 8.8 | 22 | NO | NO |
CVE-2020-8797MEDIUM Juplink RX4-1500 v1.0.3 allows remote attackers to gain root access to the Linux subsystem via an unsanitized exec call (aka Command Line Injection), if the undocumented telnetd se | Apr 23, 2020 | 6.7 | 20 | NO | NO |
CVE-2020-8798MEDIUM httpd in Juplink RX4-1500 v1.0.3-v1.0.5 allows remote attackers to change or access router settings by connecting to the unauthenticated setup3.htm endpoint from the local network. | Apr 23, 2020 | 5.5 | 18 | NO | NO |
Signals from CVEs in this vendor scope (7 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Juplink.
Media articles that mention a CVE ID that affects a product developed by Juplink — matched by CVE ID, not by vendor name.