Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Korenix

First CVE: Aug 21, 2012Active for: 14 yearsTotal CVEs: 14
41.2
VTI Score
High

Korenix manufactures industrial networking appliances, particularly its JetWave product line of managed switches and gateways designed for mission-critical automation and infrastructure environments. Vulnerabilities affecting the vendor skew strongly toward critical severity and recur through a consistent set of weaknesses—hard-coded credentials, command injection, cross-site request forgery, hidden functionality, and improper authentication—that reflect inadequate input sanitization and access controls in embedded web interfaces and management protocols. Current exploitation activity, severity distribution, and exposure metrics are shown alongside this summary.

FAUCET AI Generated
14
Total CVEs
More Total CVEs than 94% of tracked vendors
0.0
Avg CVEs / Product / Year
Bottom 1%
8.7
Avg CVSS Score
Higher Avg CVSS Score than 83% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Korenix over time

Volume of CVEsAvg CVSS Base Score
First CVE
Aug 21, 2012
13 years ago
Most Recent CVE
Jan 9, 2024
927 days ago

Products(180 total)

Top CVEs

Signals from CVEs in this vendor scope (14 CVEs).

14 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2020-12503HIGH
Improper Authorization vulnerability of Pepperl+Fuchs P+F Comtrol RocketLinx ES7510-XT, ES8509-XT, ES8510-XT, ES9528-XTv2, ES7506, ES7510, ES7528, ES8508, ES8508F, ES8510, ES8510-X
Oct 15, 20207.235NONO
CVE-2012-4577HIGH
The Linux firmware image on (1) Korenix Jetport 5600 series serial-device servers and (2) ORing Industrial DIN-Rail serial-device servers has a hardcoded password of "password" for
Aug 21, 201210.033NONO
CVE-2017-14027CRITICAL
A Use of Hard-coded Credentials issue was discovered in Korenix JetNet JetNet5018G version 1.4, JetNet5310G version 1.4a, JetNet5428G-2G-2FX version 1.4, JetNet5628G-R version 1.4,
Nov 1, 20179.832NONO
CVE-2020-12501CRITICAL
Improper Authorization vulnerability of Pepperl+Fuchs P+F Comtrol RocketLinx ES7510-XT, ES8509-XT, ES8510-XT, ES9528-XTv2, ES7506, ES7510, ES7528, ES8508, ES8508F, ES8510, ES8510-X
Oct 15, 20209.831NONO
CVE-2017-14021CRITICAL
A Use of Hard-coded Cryptographic Key issue was discovered in Korenix JetNet JetNet5018G version 1.4, JetNet5310G version 1.4a, JetNet5428G-2G-2FX version 1.4, JetNet5628G-R versio
Nov 1, 20179.830NONO
CVE-2023-5347CRITICAL
An Improper Verification of Cryptographic Signature vulnerability in the update process of Korenix JetNet Series allows replacing the whole operating system including Trusted Execu
Jan 9, 20249.129NONO
CVE-2021-39280HIGH
Certain Korenix JetWave devices allow authenticated users to execute arbitrary code as root via /syscmd.asp. This affects 2212X before 1.9.1, 2212S before 1.9.1, 2212G before 1.8,
Feb 6, 20228.828NONO
CVE-2023-5376CRITICAL
An Improper Authentication vulnerability in Korenix JetNet TFTP allows abuse of this service. This issue affects JetNet devices older than firmware version 2024/01.
Jan 9, 20249.127NONO
CVE-2023-23295HIGH
Korenix Jetwave 4200 Series 1.3.0 and JetWave 3000 Series 1.6.0 are vulnerable to Command Injection via /goform/formSysCmd. An attacker an modify the sysCmd parameter in order to e
Feb 23, 20238.827NONO
CVE-2023-23294HIGH
Korenix JetWave 4200 Series 1.3.0 and JetWave 3000 Series 1.6.0 are vulnerable to Command Injection. An attacker can modify the file_name parameter to execute commands as root.
Feb 23, 20238.827NONO
View all 14 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products14 CVEs
14%
43%
43%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network13 (92.9%)
Unknown1 (7.1%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low13 (92.9%)
High0 (0.0%)
Unknown1 (7.1%)
User Interaction
None11 (78.6%)
Unknown1 (7.1%)
Required2 (14.3%)
Privileges Required
Low4 (28.6%)
High1 (7.1%)
None8 (57.1%)
Unknown1 (7.1%)

Exploit Exposure

Signals from CVEs in this vendor scope (14 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Korenix.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Korenix — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Korenix's Products

View all 4 CNAs →

Top CWEs