Multilaser manufactures a focused line of network routing and connectivity devices, including models such as the RE160 and RE163V, that serve small-business and residential deployments. Vulnerabilities affecting these products skew strongly toward critical severity and frequently acquire public exploit code, and recur through web-facing input-handling and access-control weaknesses including cross-site scripting, cross-site request forgery, improper access control, and exposure of sensitive information. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Multilaser over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-31152HIGH Multilaser Router AC1200 V02.03.01.45_pt contains a cross-site request forgery (CSRF) vulnerability. An attacker can enable remote access, change passwords, and perform other actio | Apr 14, 2021 | 8.8 | 38 | NO | YES |
CVE-2023-38944CRITICAL An issue in Multilaser RE160V firmware v12.03.01.09_pt and Multilaser RE163V firmware v12.03.01.10_pt allows attackers to bypass the access control and gain complete access to the | Mar 6, 2024 | 9.8 | 34 | NO | NO |
CVE-2023-38945CRITICAL Multilaser RE160 v5.07.51_pt_MTL01 and v5.07.52_pt_MTL01, Multilaser RE160V v12.03.01.08_pt and V12.03.01.09_pt, and Multilaser RE163V v12.03.01.08_pt allows attackers to bypass th | Mar 6, 2024 | 9.8 | 27 | NO | NO |
CVE-2023-38946HIGH An issue in Multilaser RE160 firmware v5.07.51_pt_MTL01 and v5.07.52_pt_MTL01 allows attackers to bypass the access control and gain complete access to the application via supplyin | Mar 6, 2024 | 8.8 | 24 | NO | NO |
CVE-2023-0658HIGH A vulnerability, which was classified as critical, was found in Multilaser RE057 and RE170 2.1/2.2. This affects an unknown part of the file /param.file.tgz of the component Backup | Feb 3, 2023 | 7.5 | 24 | NO | NO |
CVE-2023-36146MEDIUM A Stored Cross-Site Scripting (XSS) vulnerability was found in Multilaser RE 170 using firmware 2.2.6733. | Jun 30, 2023 | 5.4 | 19 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Multilaser.
Media articles that mention a CVE ID that affects a product developed by Multilaser — matched by CVE ID, not by vendor name.