Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Melag

First CVE: Jun 24, 2022Active for: 4 yearsTotal CVEs: 6

Melag manufactures medical sterilization and laboratory equipment, with a modest vulnerability footprint concentrated in an FTP server component embedded in its device offerings. The recurring exposure centers on configuration and authentication weaknesses—including incorrect default permissions, cleartext storage of sensitive data, improper authentication mechanisms, path traversal, and observable discrepancies—that are characteristic of legacy embedded systems where security hardening was secondary to functionality. Current severity, exploitation, and exposure figures are shown alongside this summary.

FAUCET AI Generated
6
Total CVEs
More Total CVEs than 86% of tracked vendors
6.0
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 98% of tracked vendors
6.8
Avg CVSS Score
Higher Avg CVSS Score than 45% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Melag over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jun 24, 2022
4 years ago
Most Recent CVE
Jun 24, 2022
1,491 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (6 CVEs).

6 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2021-41635HIGH
When installed as Windows service MELAG FTP Server 2.2.0.4 is run as SYSTEM user, which grants remote attackers to abuse misconfigurations or vulnerabilities with administrative ac
Jun 24, 20228.828NONO
CVE-2021-41638HIGH
The authentication checks of the MELAG FTP Server in version 2.2.0.4 are incomplete, which allows a remote attacker to access local files only by using a valid username.
Jun 24, 20227.524NONO
CVE-2021-41637HIGH
Weak access control permissions in MELAG FTP Server 2.2.0.4 allow the "Everyone" group to read the local FTP configuration file, which includes among other information the unencryp
Jun 24, 20227.123NONO
CVE-2021-41636MEDIUM
MELAG FTP Server 2.2.0.4 allows an attacker to use the CWD command to break out of the FTP servers root directory and operate on the entire operating system, while the access restr
Jun 24, 20226.522NONO
CVE-2021-41634MEDIUM
A user enumeration vulnerability in MELAG FTP Server 2.2.0.4 allows an attacker to identify valid FTP usernames.
Jun 24, 20225.320NONO
CVE-2021-41639MEDIUM
MELAG FTP Server 2.2.0.4 stores unencrpyted passwords of FTP users in a local configuration file.
Jun 24, 20225.519NONO
View all 6 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products6 CVEs
50%
50%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local2 (33.3%)
Network4 (66.7%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low6 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None6 (100.0%)
Unknown0 (0.0%)
Required0 (0.0%)
Privileges Required
Low4 (66.7%)
High0 (0.0%)
None2 (33.3%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (6 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Melag.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Melag — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Melag's Products

View all 1 CNAs →

Top CWEs