Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Ovarro

First CVE: Jul 28, 2022Active for: 4 yearsTotal CVEs: 12
27.6
VTI Score
Low

Ovarro manufactures the TBOX line of embedded control and monitoring systems deployed in critical water and utility infrastructure, where a small, focused product family carries outsized operational significance due to the sector's dependency on reliable automation and remote access. Vulnerabilities affecting these systems skew strongly toward critical severity and cluster around authentication and authorization weaknesses—capture-replay attacks, cleartext credential storage, improper access control, code injection, and path-traversal flaws—that are characteristic of legacy embedded firmware where modern security controls are often absent or difficult to retrofit. Defenders should treat advisories for this vendor as high-priority for water utilities and industrial environments where these devices gate critical operations; live severity and exploitation counts are shown alongside this summary.

FAUCET AI Generated
12
Total CVEs
More Total CVEs than 93% of tracked vendors
0.4
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 4% of tracked vendors
7.9
Avg CVSS Score
Higher Avg CVSS Score than 76% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Ovarro over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jul 28, 2022
3 years ago
Most Recent CVE
Jul 3, 2023
1,117 days ago

Products(17 total)

Top CVEs

Signals from CVEs in this vendor scope (12 CVEs).

12 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2021-22650CRITICAL
An attacker may use TWinSoft and a malicious source project file (TPG) to extract files on machine executing Ovarro TWinSoft, which could lead to code execution.
Jul 28, 20229.830NONO
CVE-2021-22648CRITICAL
Ovarro TBox proprietary Modbus file access functions allow attackers to read, alter, or delete the configuration file.
Jul 28, 20229.830NONO
CVE-2021-22646CRITICAL
The “ipk” package containing the configuration created by TWinSoft can be uploaded, extracted, and executed in Ovarro TBox, allowing malicious code execution.
Jul 28, 20229.830NONO
CVE-2021-22644CRITICAL
Ovarro TBox TWinSoft uses the custom hardcoded user “TWinSoft” with a hardcoded key.
Jul 28, 20229.830NONO
CVE-2021-22640CRITICAL
An attacker can decrypt the Ovarro TBox login password by communication capture and brute force attacks.
Jul 28, 20229.830NONO
CVE-2021-22642HIGH
An attacker could use specially crafted invalid Modbus frames to crash the Ovarro TBox system.
Jul 28, 20227.524NONO
CVE-2023-36611MEDIUM
The affected TBox RTUs allow low privilege users to access software security tokens of higher privilege. This could allow an attacker with “user” privileges to access files requir
Jul 3, 20236.521NONO
CVE-2023-36609HIGH
The affected TBox RTUs run OpenVPN with root privileges and can run user defined configuration scripts. An attacker could set up a local OpenVPN server and push a malicious script
Jul 3, 20237.221NONO
CVE-2023-3395MEDIUM
​All versions of the TWinSoft Configuration Tool store encrypted passwords as plaintext in memory. An attacker with access to system files could open a file to load the document i
Jul 3, 20236.519NONO
CVE-2023-36610MEDIUM
​The affected TBox RTUs generate software security tokens using insufficient entropy. The random seed used to generate the software tokens is not initialized correctly, and other
Jul 3, 20235.919NONO
View all 12 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products12 CVEs
42%
17%
42%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network12 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low11 (91.7%)
High1 (8.3%)
Unknown0 (0.0%)
User Interaction
None12 (100.0%)
Unknown0 (0.0%)
Required0 (0.0%)
Privileges Required
Low3 (25.0%)
High1 (8.3%)
None8 (66.7%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (12 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Ovarro.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Ovarro — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Ovarro's Products

View all 1 CNAs →

Top CWEs