Ovarro manufactures the TBOX line of embedded control and monitoring systems deployed in critical water and utility infrastructure, where a small, focused product family carries outsized operational significance due to the sector's dependency on reliable automation and remote access. Vulnerabilities affecting these systems skew strongly toward critical severity and cluster around authentication and authorization weaknesses—capture-replay attacks, cleartext credential storage, improper access control, code injection, and path-traversal flaws—that are characteristic of legacy embedded firmware where modern security controls are often absent or difficult to retrofit. Defenders should treat advisories for this vendor as high-priority for water utilities and industrial environments where these devices gate critical operations; live severity and exploitation counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Ovarro over time
Signals from CVEs in this vendor scope (12 CVEs).
12 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-22650CRITICAL An attacker may use TWinSoft and a malicious source project file (TPG) to extract files on machine executing Ovarro TWinSoft, which could lead to code execution. | Jul 28, 2022 | 9.8 | 30 | NO | NO |
CVE-2021-22648CRITICAL Ovarro TBox proprietary Modbus file access functions allow attackers to read, alter, or delete the configuration file. | Jul 28, 2022 | 9.8 | 30 | NO | NO |
CVE-2021-22646CRITICAL The “ipk” package containing the configuration created by TWinSoft can be uploaded, extracted, and executed in Ovarro TBox, allowing malicious code execution. | Jul 28, 2022 | 9.8 | 30 | NO | NO |
CVE-2021-22644CRITICAL Ovarro TBox TWinSoft uses the custom hardcoded user “TWinSoft” with a hardcoded key. | Jul 28, 2022 | 9.8 | 30 | NO | NO |
CVE-2021-22640CRITICAL An attacker can decrypt the Ovarro TBox login password by communication capture and brute force attacks. | Jul 28, 2022 | 9.8 | 30 | NO | NO |
CVE-2021-22642HIGH An attacker could use specially crafted invalid Modbus frames to crash the Ovarro TBox system. | Jul 28, 2022 | 7.5 | 24 | NO | NO |
CVE-2023-36611MEDIUM
The affected TBox RTUs allow low privilege users to access software security tokens of higher privilege. This could allow an attacker with “user” privileges to access files requir | Jul 3, 2023 | 6.5 | 21 | NO | NO |
CVE-2023-36609HIGH
The affected TBox RTUs run OpenVPN with root privileges and can run user defined configuration scripts. An attacker could set up a local OpenVPN server and push a malicious script | Jul 3, 2023 | 7.2 | 21 | NO | NO |
CVE-2023-3395MEDIUM
All versions of the TWinSoft Configuration Tool store encrypted passwords as plaintext in memory. An attacker with access to system files could open a file to load the document i | Jul 3, 2023 | 6.5 | 19 | NO | NO |
CVE-2023-36610MEDIUM
The affected TBox RTUs generate software security tokens using insufficient entropy. The random seed used to generate the software tokens is not initialized correctly, and other | Jul 3, 2023 | 5.9 | 19 | NO | NO |
Signals from CVEs in this vendor scope (12 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Ovarro.
Media articles that mention a CVE ID that affects a product developed by Ovarro — matched by CVE ID, not by vendor name.