Optilinknetwork's vulnerability footprint centers on its XT71000N networking appliance and firmware, a narrowly scoped but prominent product line in its deployment class. Vulnerabilities affecting this vendor skew toward serious outcomes, with an elevated share reaching critical severity, and cluster around web-interface and command-execution weaknesses including cross-site request forgery, command injection, and unrestricted file upload that are characteristic of internet-facing network devices. Current severity and exploitation counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Optilinknetwork over time
Signals from CVEs in this vendor scope (12 CVEs).
12 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-23584CRITICAL Unauthenticated remote code execution in OPTILINK OP-XT71000N, Hardware Version: V2.2 occurs when the attacker passes arbitrary commands with IP-ADDRESS using " | " to execute comm | Nov 23, 2022 | 9.8 | 54 | NO | NO |
CVE-2020-23591CRITICAL A vulnerability in OPTILINK OP-XT71000N Hardware Version: V2.2 , Firmware Version: OP_V3.3.1-191028 allows an attacker to upload arbitrary files through " /mgm_dev_upgrade.asp " wh | Nov 23, 2022 | 9.8 | 31 | NO | NO |
CVE-2020-23592HIGH A vulnerability in OPTILINK OP-XT71000N Hardware Version: V2.2 , Firmware Version: OP_V3.3.1-191028 allows an unauthenticated, remote attacker to conduct a cross-site request forge | Nov 23, 2022 | 8.8 | 28 | NO | NO |
CVE-2020-23585HIGH A remote attacker can conduct a cross-site request forgery (CSRF) attack on OPTILINK OP-XT71000N Hardware Version: V2.2 , Firmware Version: OP_V3.3.1-191028. The vulnerability is d | Nov 23, 2022 | 8.8 | 28 | NO | NO |
CVE-2020-23583CRITICAL OPTILINK OP-XT71000N V2.2 is vulnerable to Remote Code Execution. The issue occurs when the attacker sends an arbitrary code on "/diag_ping_admin.asp" to "PingTest" interface that | Nov 23, 2022 | 9.8 | 24 | NO | NO |
CVE-2020-23589MEDIUM A vulnerability in OPTILINK OP-XT71000N Hardware Version: V2.2 , Firmware Version: OP_V3.3.1-191028 allows an unauthenticated, remote attacker to conduct a cross-site request forge | Nov 23, 2022 | 6.5 | 23 | NO | NO |
CVE-2020-23593MEDIUM A vulnerability in OPTILINK OP-XT71000N Hardware Version: V2.2, Firmware Version: OP_V3.3.1-191028 allows an unauthenticated, remote attacker to conduct a cross site request forger | Nov 23, 2022 | 6.5 | 23 | NO | NO |
CVE-2020-23582MEDIUM A vulnerability in the "/admin/wlmultipleap.asp" of optilink OP-XT71000N version: V2.2 could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF | Nov 21, 2022 | 6.5 | 23 | NO | NO |
CVE-2020-23588MEDIUM A vulnerability in OPTILINK OP-XT71000N Hardware Version: V2.2 , Firmware Version: OP_V3.3.1-191028 allows an unauthenticated, remote attacker to conduct a cross-site request forge | Nov 23, 2022 | 4.3 | 18 | NO | NO |
CVE-2020-23586MEDIUM A vulnerability found in OPTILINK OP-XT71000N Hardware Version: V2.2 , Firmware Version: OP_V3.3.1-191028 allows an unauthenticated, remote attacker to conduct a cross-site request | Nov 23, 2022 | 4.3 | 18 | NO | NO |
Signals from CVEs in this vendor scope (12 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Optilinknetwork.
Media articles that mention a CVE ID that affects a product developed by Optilinknetwork — matched by CVE ID, not by vendor name.