Martem develops a focused line of telemetry gateway products, including the Telem-GW6 and Telem-GWM series, that aggregate and relay network monitoring data in industrial and utility environments. The observed vulnerability signal centers on authentication and default-configuration weaknesses—improper authentication checks, missing guards on critical functions, insecure initialization defaults, and cross-site scripting in web interfaces—that are characteristic of networked appliances where administrative access and data integrity are primary concerns. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Martem over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-10603CRITICAL Martem TELEM GW6 and GWM devices with firmware 2018.04.18-linux_4-01-601cb47 and prior do not perform authentication of IEC-104 control commands, which may allow a rogue node a rem | Jul 31, 2018 | 9.8 | 30 | NO | NO |
CVE-2018-10605HIGH Martem TELEM GW6/GWM versions prior to 2.0.87-4018403-k4 may allow unprivileged users to modify/upload a new system configuration or take the full control over the RTU using defaul | Oct 1, 2018 | 8.8 | 27 | NO | NO |
CVE-2018-10607HIGH Martem TELEM GW6 and GWM devices with firmware 2018.04.18-linux_4-01-601cb47 and prior allow the creation of new connections to one or more IOAs, without closing them properly, whi | Jul 31, 2018 | 7.5 | 24 | NO | NO |
CVE-2018-10609MEDIUM Martem TELEM GW6 and GWM devices with firmware 2018.04.18-linux_4-01-601cb47 and prior allow improper sanitization of data over a Websocket which may allow cross-site scripting and | Jul 31, 2018 | 6.1 | 21 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Martem.
Media articles that mention a CVE ID that affects a product developed by Martem — matched by CVE ID, not by vendor name.