Nvki's vulnerability footprint is centered on its intelligent broadband subscriber gateway product, a narrowly scoped networking appliance deployed in service-provider environments. The observed weakness classes—command injection, SQL injection, and hard-coded credentials—reflect input-handling and authentication concerns typical of gateway firmware and backend management interfaces. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Nvki over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-39809CRITICAL N.V.K.INTER CO., LTD. (NVK) iBSG v3.5 was discovered to contain an OS command injection vulnerability via shell metacharacters in the system_hostname parameter at /manage/network-b | Aug 21, 2023 | 9.8 | 29 | NO | NO |
CVE-2023-39807CRITICAL N.V.K.INTER CO., LTD. (NVK) iBSG v3.5 was discovered to contain a SQL injection vulnerability via the a_passwd parameter at /portal/user-register.php. | Aug 21, 2023 | 9.8 | 28 | NO | NO |
CVE-2023-39808CRITICAL N.V.K.INTER CO., LTD. (NVK) iBSG v3.5 was discovered to contain a hardcoded root password that allows attackers to login with root privileges via the SSH service. The cleartext pas | Aug 21, 2023 | 9.8 | 26 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Nvki.
Media articles that mention a CVE ID that affects a product developed by Nvki — matched by CVE ID, not by vendor name.