Kraftway's vulnerability profile centers on a narrowly scoped embedded router and firmware product line that, despite modest disclosure volume, skews toward critical-severity outcomes. The recurring weakness classes—including improper memory-buffer restrictions, insecure link resolution, weak cryptographic defaults, and initialization flaws—reflect the firmware and embedded-systems challenges common to networking appliances. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Kraftway over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-15353CRITICAL A Buffer Overflow exploited through web interface by remote attacker can cause remote code execution in Kraftway 24F2XG Router firmware 3.5.30.1118. | Aug 17, 2018 | 9.8 | 34 | NO | NO |
CVE-2018-15350CRITICAL Router Default Credentials in Kraftway 24F2XG Router firmware version 3.5.30.1118 allow remote attackers to get privileged access to the router. | Aug 17, 2018 | 9.8 | 31 | NO | NO |
CVE-2018-15354HIGH A Buffer Overflow exploited through web interface by remote attacker can cause denial of service in Kraftway 24F2XG Router firmware 3.5.30.1118. | Aug 17, 2018 | 7.5 | 24 | NO | NO |
CVE-2018-15352MEDIUM An attacker with low privileges can cause denial of service in Kraftway 24F2XG Router firmware version 3.5.30.1118. | Aug 17, 2018 | 6.5 | 22 | NO | NO |
CVE-2018-15351MEDIUM Denial of service via crafting malicious link and sending it to a privileged user can cause Denial of Service in Kraftway 24F2XG Router firmware version 3.5.30.1118. | Aug 17, 2018 | 6.5 | 22 | NO | NO |
CVE-2018-15355MEDIUM Usage of SSLv2 and SSLv3 leads to transmitted data decryption in Kraftway 24F2XG Router firmware 3.5.30.1118. | Aug 17, 2018 | 5.9 | 20 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Kraftway.
Media articles that mention a CVE ID that affects a product developed by Kraftway — matched by CVE ID, not by vendor name.