LFEdge maintains a focused set of edge-computing and IoT orchestration products, including EKuiper and EVE, that operate at the boundary between enterprise networks and distributed edge devices. Vulnerabilities affecting this vendor skew toward serious outcomes, with a meaningful share reaching critical severity, and recur through weakness classes centered on data-handling and credential-protection deficiencies—including SQL injection, cross-site scripting, insecure credential storage, and hard-coded secrets—that are characteristic of middleware platforms interfacing with heterogeneous endpoints. Current severity, exploitation status, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Lfedge over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-54379CRITICAL LF Edge eKuiper is a lightweight IoT data analytics and stream processing engine running on resource-constraint edge devices. In versions before 2.2.1, there is a critical SQL Inje | Jul 24, 2025 | 9.8 | 31 | NO | NO |
CVE-2023-43634HIGH
When sealing/unsealing the “vault” key, a list of PCRs is used, which defines which PCRs
are used.
In a previous project, CYMOTIVE found that the configuration is not protected b | Sep 21, 2023 | 8.8 | 27 | NO | NO |
CVE-2023-43633HIGH
On boot, the Pillar eve container checks for the existence and content of
“/config/GlobalConfig/global.json”.
If the file exists, it overrides the existing configuration on the d | Sep 21, 2023 | 8.8 | 26 | NO | NO |
CVE-2024-43406HIGH LF Edge eKuiper is a lightweight IoT data analytics and stream processing engine running on resource-constraint edge devices. A user could utilize and exploit SQL Injection to allo | Aug 20, 2024 | 8.8 | 25 | NO | NO |
CVE-2023-43637HIGH
Due to the implementation of "deriveVaultKey", prior to version 7.10, the generated vault key
would always have the last 16 bytes predetermined to be "arfoobarfoobarfo".
This iss | Sep 21, 2023 | 7.8 | 24 | NO | NO |
CVE-2024-52290MEDIUM LF Edge eKuiper is a lightweight internet of things (IoT) data analytics and stream processing engine. Prior to version 2.1.0 user with rights to modificate the service (e.g. kuipe | May 14, 2025 | 5.4 | 17 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Lfedge.
Media articles that mention a CVE ID that affects a product developed by Lfedge — matched by CVE ID, not by vendor name.