Netmotionsoftware maintains a narrowly focused mobile device management and remote access platform, Netmotion Mobility, whose security footprint is concentrated in enterprise endpoint control. The vendor's disclosures recur through deserialization of untrusted data and incorrect permission assignment for critical resources, reflecting the authentication and code-execution surface inherent to a management agent that bridges endpoints and corporate infrastructure. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Netmotionsoftware over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-26914HIGH NetMotion Mobility before 11.73 and 12.x before 12.02 allows unauthenticated remote attackers to execute arbitrary code as SYSTEM because of Java deserialization in MvcUtil valueSt | Feb 8, 2021 | 8.1 | 77 | NO | YES |
CVE-2021-26912HIGH NetMotion Mobility before 11.73 and 12.x before 12.02 allows unauthenticated remote attackers to execute arbitrary code as SYSTEM because of Java deserialization in SupportRpcServl | Feb 8, 2021 | 8.1 | 46 | NO | NO |
CVE-2021-26915HIGH NetMotion Mobility before 11.73 and 12.x before 12.02 allows unauthenticated remote attackers to execute arbitrary code as SYSTEM because of Java deserialization in webrepdb Status | Feb 8, 2021 | 8.1 | 45 | NO | NO |
CVE-2021-26913HIGH NetMotion Mobility before 11.73 and 12.x before 12.02 allows unauthenticated remote attackers to execute arbitrary code as SYSTEM because of Java deserialization in RpcServlet. | Feb 8, 2021 | 8.1 | 30 | NO | NO |
CVE-2021-40067MEDIUM The access controls on the Mobility read-write API improperly validate user access permissions; this API is disabled by default. If the API is manually enabled, attackers with both | Sep 16, 2021 | 6.8 | 23 | NO | NO |
CVE-2021-40066MEDIUM The access controls on the Mobility read-only API improperly validate user access permissions. Attackers with both network access to the API and valid credentials can read data fro | Sep 16, 2021 | 5.3 | 20 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Netmotionsoftware.
Media articles that mention a CVE ID that affects a product developed by Netmotionsoftware — matched by CVE ID, not by vendor name.