Multi Tech produces a narrowly scoped proxy server product with a minimal observed vulnerability footprint. Current exploitation activity, severity distribution, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Multi Tech over time
Signals from CVEs in this vendor scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2016-10512CRITICAL MultiTech FaxFinder before 4.1.2 stores Passwords unencrypted for maintaining the test connectivity function of its LDAP configuration. These credentials are retrieved by the syste | Sep 30, 2017 | 9.8 | 28 | NO | NO |
CVE-2003-0125MEDIUM Buffer overflow in the web interface for SOHO Routefinder 550 before firmware 4.63 allows remote attackers to cause a denial of service (reboot) and execute arbitrary code via a lo | Mar 18, 2003 | 5.0 | 26 | NO | YES |
CVE-2002-1629HIGH Multi-Tech ProxyServer products MTPSR1-100, MTPSR1-120, MTPSR1-202ST, MTPSR2-201, and MTPSR3-200 ship with a null password, which allows remote attackers to gain administrative pri | Dec 31, 2002 | 10.0 | 26 | NO | NO |
CVE-2023-25201HIGH Cross Site Request Forgery (CSRF) vulnerability in MultiTech Conduit AP MTCAP2-L4E1 MTCAP2-L4E1-868-042A v.6.0.0 allows a remote attacker to execute arbitrary code via a crafted sc | Jul 7, 2023 | 8.8 | 24 | NO | NO |
CVE-2018-17562HIGH Multi-Tech FaxFinder before 5.1.6 has SQL Injection via a status/call_details?oid= URI, allowing an attacker to extract the underlying database schema to further disclose other fax | Oct 3, 2018 | 7.5 | 24 | NO | NO |
CVE-2020-7594HIGH MultiTech Conduit MTCDT-LVW2-24XX 1.4.17-ocea-13592 devices allow remote authenticated administrators to execute arbitrary OS commands by navigating to the Debug Options page and e | Jan 21, 2020 | 7.2 | 23 | NO | NO |
CVE-2003-0126HIGH The web interface for SOHO Routefinder 550 firmware 4.63 and earlier, and possibly later versions, has a default "admin" account with a blank password, which could allow attackers | Mar 18, 2003 | 7.5 | 21 | NO | NO |
Signals from CVEs in this vendor scope (7 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Multi Tech.
Media articles that mention a CVE ID that affects a product developed by Multi Tech — matched by CVE ID, not by vendor name.