Nedi is a network-discovery and management platform with a concentrated product footprint centered on a single flagship appliance. The vendor's vulnerability profile reflects characteristic challenges of web-facing administrative interfaces: a persistent pattern of input-validation and privilege-boundary weaknesses including cross-site scripting, OS command injection, SQL injection, CSRF, and improper authorization checks. These weakness classes recur because the product handles user-supplied network data and exposes administrative functions through a web portal, creating both breadth of input sources and high impact from successful exploitation. A meaningful share of the vendor's disclosures reach serious severity, warranting prompt attention to updates; current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Nedi over time
Signals from CVEs in this vendor scope (26 CVEs).
26 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-14413MEDIUM NeDi 1.9C is vulnerable to XSS because of an incorrect implementation of sanitize() in inc/libmisc.php. This function attempts to escape the SCRIPT tag from user-controllable value | Jun 29, 2020 | 6.1 | 32 | NO | YES |
CVE-2022-40895CRITICAL In certain Nedi products, a vulnerability in the web UI of NeDi login & Community login could allow an unauthenticated, remote attacker to affect the integrity of a device via a Us | Oct 6, 2022 | 9.1 | 29 | NO | NO |
CVE-2021-26753CRITICAL NeDi 1.9C allows an authenticated user to inject PHP code in the System Files function on the endpoint /System-Files.php via the txt HTTP POST parameter. This allows an attacker to | Feb 12, 2021 | 9.9 | 29 | NO | NO |
CVE-2020-14414HIGH NeDi 1.9C is vulnerable to Remote Command Execution. pwsec.php improperly escapes shell metacharacters from a POST request. An attacker can exploit this by crafting an arbitrary pa | Jun 29, 2020 | 8.8 | 29 | NO | NO |
CVE-2020-14412HIGH NeDi 1.9C is vulnerable to Remote Command Execution. System-Snapshot.php improperly escapes shell metacharacters from a POST request. An attacker can exploit this by crafting an ar | Jun 29, 2020 | 8.8 | 29 | NO | NO |
CVE-2018-20727HIGH Multiple command injection vulnerabilities in NeDi before 1.7Cp3 allow authenticated users to execute code on the server side via the flt parameter to Nodes-Traffic.php, the dv par | Jan 17, 2019 | 8.8 | 29 | NO | NO |
CVE-2021-26752HIGH NeDi 1.9C allows an authenticated user to execute operating system commands in the Nodes Traffic function on the endpoint /Nodes-Traffic.php via the md or ag HTTP GET parameter. Th | Feb 12, 2021 | 8.8 | 27 | NO | NO |
CVE-2021-26751HIGH NeDi 1.9C allows an authenticated user to perform a SQL Injection in the Monitoring History function on the endpoint /Monitoring-History.php via the det HTTP GET parameter. This al | Feb 12, 2021 | 8.8 | 27 | NO | NO |
CVE-2018-20728HIGH A cross site request forgery (CSRF) vulnerability in NeDi before 1.7Cp3 allows remote attackers to escalate privileges via User-Management.php. | Jan 17, 2019 | 8.8 | 27 | NO | NO |
CVE-2018-20730HIGH A SQL injection vulnerability in NeDi before 1.7Cp3 allows any user to execute arbitrary SQL read commands via the query.php component. | Jan 17, 2019 | 7.5 | 24 | NO | NO |
Signals from CVEs in this vendor scope (26 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Nedi.
Media articles that mention a CVE ID that affects a product developed by Nedi — matched by CVE ID, not by vendor name.