Kslabs maintains a focused web-server product, Ksweb, with a modest vulnerability footprint centered on file-handling and directory-access controls. The recurring exposure reflects path-traversal and unrestricted-upload weaknesses typical of web-facing applications where input validation and access boundaries are critical; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Kslabs over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-15766HIGH The KSLABS KSWEB (aka ru.kslabs.ksweb) application 3.93 for Android allows authenticated remote code execution via a POST request to the AJAX handler with the configFile parameter | Oct 3, 2019 | 8.8 | 28 | NO | NO |
CVE-2019-16198MEDIUM KSLabs KSWEB 3.93 allows ../ directory traversal, as demonstrated by the hostFile parameter. | Oct 3, 2019 | 6.5 | 22 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Kslabs.
Media articles that mention a CVE ID that affects a product developed by Kslabs — matched by CVE ID, not by vendor name.