Melag manufactures medical sterilization and laboratory equipment, with a modest vulnerability footprint concentrated in an FTP server component embedded in its device offerings. The recurring exposure centers on configuration and authentication weaknesses—including incorrect default permissions, cleartext storage of sensitive data, improper authentication mechanisms, path traversal, and observable discrepancies—that are characteristic of legacy embedded systems where security hardening was secondary to functionality. Current severity, exploitation, and exposure figures are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Melag over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-41635HIGH When installed as Windows service MELAG FTP Server 2.2.0.4 is run as SYSTEM user, which grants remote attackers to abuse misconfigurations or vulnerabilities with administrative ac | Jun 24, 2022 | 8.8 | 28 | NO | NO |
CVE-2021-41638HIGH The authentication checks of the MELAG FTP Server in version 2.2.0.4 are incomplete, which allows a remote attacker to access local files only by using a valid username. | Jun 24, 2022 | 7.5 | 24 | NO | NO |
CVE-2021-41637HIGH Weak access control permissions in MELAG FTP Server 2.2.0.4 allow the "Everyone" group to read the local FTP configuration file, which includes among other information the unencryp | Jun 24, 2022 | 7.1 | 23 | NO | NO |
CVE-2021-41636MEDIUM MELAG FTP Server 2.2.0.4 allows an attacker to use the CWD command to break out of the FTP servers root directory and operate on the entire operating system, while the access restr | Jun 24, 2022 | 6.5 | 22 | NO | NO |
CVE-2021-41634MEDIUM A user enumeration vulnerability in MELAG FTP Server 2.2.0.4 allows an attacker to identify valid FTP usernames. | Jun 24, 2022 | 5.3 | 20 | NO | NO |
CVE-2021-41639MEDIUM MELAG FTP Server 2.2.0.4 stores unencrpyted passwords of FTP users in a local configuration file. | Jun 24, 2022 | 5.5 | 19 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Melag.
Media articles that mention a CVE ID that affects a product developed by Melag — matched by CVE ID, not by vendor name.