Merit maintains a focused AAA and RADIUS authentication server product line serving network access control deployments. The observed vulnerability signals center on the authentication infrastructure role and the complexity of protocol parsing inherent to RADIUS implementations, though live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Merit over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2001-0534HIGH Multiple buffer overflows in RADIUS daemon radiusd in (1) Merit 3.6b and (2) Lucent 2.1-2 RADIUS allow remote attackers to cause a denial of service or execute arbitrary commands. | Jul 21, 2001 | 10.0 | 27 | NO | NO |
rlmadmin RADIUS management utility in Merit AAA Server 3.8M, 5.01, and possibly other versions, allows local users to read arbitrary files via a symlink attack on the rlmadmin.help | Sep 7, 2001 | 2.1 | 18 | NO | YES |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Merit.
Media articles that mention a CVE ID that affects a product developed by Merit — matched by CVE ID, not by vendor name.