Mimosa develops a focused line of wireless backhaul and client radio products, including its B5 series, that operate in point-to-point and point-to-multipoint network configurations. The durable signal in its vulnerability profile centers on input-handling and output-encoding weaknesses such as injection, cross-site scripting, OS command injection, and improper input validation, alongside exposure of sensitive information—a pattern typical of networked appliances where web-based management and command processing interfaces present multiple entry points. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Mimosa over time
Signals from CVEs in this vendor scope (8 CVEs).
8 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2017-9135HIGH An issue was discovered on Mimosa Client Radios before 2.2.4 and Mimosa Backhaul Radios before 2.2.4. On the backend of the device's web interface, there are some diagnostic tests | May 21, 2017 | 8.8 | 28 | NO | NO |
CVE-2017-9133HIGH An issue was discovered on Mimosa Client Radios before 2.2.3 and Mimosa Backhaul Radios before 2.2.3. In the device's web interface, after logging in, there is a page that allows y | May 21, 2017 | 8.8 | 28 | NO | NO |
CVE-2020-25206HIGH The web console for Mimosa B5, B5c, and C5x firmware through 2.8.0.2 allows authenticated command injection in the Throughput, WANStats, PhyStats, and QosStats API classes. An atta | Jul 20, 2021 | 7.2 | 27 | NO | NO |
CVE-2017-9131HIGH An issue was discovered on Mimosa Client Radios before 2.2.3 and Mimosa Backhaul Radios before 2.2.3. By connecting to the Mosquitto broker on an access point and one of its client | May 21, 2017 | 7.5 | 26 | NO | NO |
CVE-2017-9136HIGH An issue was discovered on Mimosa Client Radios before 2.2.3. In the device's web interface, there is a page that allows an attacker to use an unsanitized GET parameter to download | May 21, 2017 | 7.5 | 25 | NO | NO |
CVE-2017-9134HIGH An information-leakage issue was discovered on Mimosa Client Radios before 2.2.3 and Mimosa Backhaul Radios before 2.2.3. There is a page in the web interface that will show you th | May 21, 2017 | 7.5 | 25 | NO | NO |
CVE-2017-9132HIGH A hard-coded credentials issue was discovered on Mimosa Client Radios before 2.2.3, Mimosa Backhaul Radios before 2.2.3, and Mimosa Access Points before 2.2.3. These devices run Mo | May 21, 2017 | 7.5 | 25 | NO | NO |
CVE-2020-25205MEDIUM The web console for Mimosa B5, B5c, and C5x firmware through 2.8.0.2 is vulnerable to stored XSS in the set_banner() function of /var/www/core/controller/index.php. An unauthentica | Jul 20, 2021 | 6.1 | 21 | NO | NO |
Signals from CVEs in this vendor scope (8 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Mimosa.
Media articles that mention a CVE ID that affects a product developed by Mimosa — matched by CVE ID, not by vendor name.