Korenix manufactures industrial networking appliances, particularly its JetWave product line of managed switches and gateways designed for mission-critical automation and infrastructure environments. Vulnerabilities affecting the vendor skew strongly toward critical severity and recur through a consistent set of weaknesses—hard-coded credentials, command injection, cross-site request forgery, hidden functionality, and improper authentication—that reflect inadequate input sanitization and access controls in embedded web interfaces and management protocols. Current exploitation activity, severity distribution, and exposure metrics are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Korenix over time
Signals from CVEs in this vendor scope (14 CVEs).
14 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-12503HIGH Improper Authorization vulnerability of Pepperl+Fuchs P+F Comtrol RocketLinx ES7510-XT, ES8509-XT, ES8510-XT, ES9528-XTv2, ES7506, ES7510, ES7528, ES8508, ES8508F, ES8510, ES8510-X | Oct 15, 2020 | 7.2 | 35 | NO | NO |
CVE-2012-4577HIGH The Linux firmware image on (1) Korenix Jetport 5600 series serial-device servers and (2) ORing Industrial DIN-Rail serial-device servers has a hardcoded password of "password" for | Aug 21, 2012 | 10.0 | 33 | NO | NO |
CVE-2017-14027CRITICAL A Use of Hard-coded Credentials issue was discovered in Korenix JetNet JetNet5018G version 1.4, JetNet5310G version 1.4a, JetNet5428G-2G-2FX version 1.4, JetNet5628G-R version 1.4, | Nov 1, 2017 | 9.8 | 32 | NO | NO |
CVE-2020-12501CRITICAL Improper Authorization vulnerability of Pepperl+Fuchs P+F Comtrol RocketLinx ES7510-XT, ES8509-XT, ES8510-XT, ES9528-XTv2, ES7506, ES7510, ES7528, ES8508, ES8508F, ES8510, ES8510-X | Oct 15, 2020 | 9.8 | 31 | NO | NO |
CVE-2017-14021CRITICAL A Use of Hard-coded Cryptographic Key issue was discovered in Korenix JetNet JetNet5018G version 1.4, JetNet5310G version 1.4a, JetNet5428G-2G-2FX version 1.4, JetNet5628G-R versio | Nov 1, 2017 | 9.8 | 30 | NO | NO |
CVE-2023-5347CRITICAL An Improper Verification of Cryptographic Signature vulnerability in the update process of Korenix JetNet Series allows replacing the whole operating system including Trusted Execu | Jan 9, 2024 | 9.1 | 29 | NO | NO |
CVE-2021-39280HIGH Certain Korenix JetWave devices allow authenticated users to execute arbitrary code as root via /syscmd.asp. This affects 2212X before 1.9.1, 2212S before 1.9.1, 2212G before 1.8, | Feb 6, 2022 | 8.8 | 28 | NO | NO |
CVE-2023-5376CRITICAL An Improper Authentication vulnerability in Korenix JetNet TFTP allows abuse of this service. This issue affects JetNet devices older than firmware version 2024/01. | Jan 9, 2024 | 9.1 | 27 | NO | NO |
CVE-2023-23295HIGH Korenix Jetwave 4200 Series 1.3.0 and JetWave 3000 Series 1.6.0 are vulnerable to Command Injection via /goform/formSysCmd. An attacker an modify the sysCmd parameter in order to e | Feb 23, 2023 | 8.8 | 27 | NO | NO |
CVE-2023-23294HIGH Korenix JetWave 4200 Series 1.3.0 and JetWave 3000 Series 1.6.0 are vulnerable to Command Injection. An attacker can modify the file_name parameter to execute commands as root. | Feb 23, 2023 | 8.8 | 27 | NO | NO |
Signals from CVEs in this vendor scope (14 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Korenix.
Media articles that mention a CVE ID that affects a product developed by Korenix — matched by CVE ID, not by vendor name.