Ozeki develops a modestly represented line of SMS gateway and messaging appliances positioned for enterprise communication infrastructure. The vendor's recurring vulnerabilities cluster around web-facing input handling and deserialization logic, spanning weakness classes including cross-site request forgery, argument injection, path traversal, and untrusted deserialization—patterns typical of web-interfaced gateway products. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Ozeki over time
Signals from CVEs in this vendor scope (12 CVEs).
12 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-14026HIGH CSV Injection (aka Excel Macro Injection or Formula Injection) exists in the Export Of Contacts feature in Ozeki NG SMS Gateway through 4.17.6 via a value that is mishandled in a C | Sep 22, 2020 | 8.8 | 27 | NO | NO |
CVE-2020-14025HIGH Ozeki NG SMS Gateway through 4.17.6 has multiple CSRF vulnerabilities. For example, an administrator, by following a link, can be tricked into making unwanted changes such as insta | Sep 22, 2020 | 8.8 | 27 | NO | NO |
CVE-2020-14022HIGH Ozeki NG SMS Gateway 4.17.1 through 4.17.6 does not check the file type when bulk importing new contacts ("Import Contacts" functionality) from a file. It is possible to upload an | Sep 22, 2020 | 8.8 | 27 | NO | NO |
CVE-2020-14029HIGH An issue was discovered in Ozeki NG SMS Gateway through 4.17.6. The RSS To SMS module processes XML files in an unsafe manner. This opens the application to an XML External Entity | Sep 18, 2020 | 7.5 | 24 | NO | NO |
CVE-2020-14030HIGH An issue was discovered in Ozeki NG SMS Gateway through 4.17.6. It stores SMS messages in .NET serialized format on the filesystem. By generating (and writing to the disk) maliciou | Sep 30, 2020 | 7.2 | 19 | NO | NO |
CVE-2020-14031HIGH An issue was discovered in Ozeki NG SMS Gateway through 4.17.6. The outbox functionality of the TXT File module can be used to delete all/most files in a folder. Because the produc | Sep 22, 2020 | 7.2 | 19 | NO | NO |
CVE-2020-14028HIGH An issue was discovered in Ozeki NG SMS Gateway through 4.17.6. By leveraging a path traversal vulnerability in the Autoreply module's Script Name, an attacker may write to or over | Sep 22, 2020 | 7.2 | 19 | NO | NO |
CVE-2020-14021MEDIUM An issue was discovered in Ozeki NG SMS Gateway through 4.17.6. The ASP.net SMS module can be used to read and validate the source code of ASP files. By altering the path, it can b | Sep 18, 2020 | 4.9 | 18 | NO | NO |
CVE-2020-14024MEDIUM Ozeki NG SMS Gateway through 4.17.6 has multiple authenticated stored and/or reflected XSS vulnerabilities via the (1) Receiver or Recipient field in the Mailbox feature, (2) OZFOR | Sep 22, 2020 | 6.1 | 17 | NO | NO |
CVE-2020-14027MEDIUM An issue was discovered in Ozeki NG SMS Gateway through 4.17.6. The database connection strings accept custom unsafe arguments, such as ENABLE_LOCAL_INFILE, that can be leveraged b | Sep 22, 2020 | 5.3 | 15 | NO | NO |
Signals from CVEs in this vendor scope (12 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Ozeki.
Media articles that mention a CVE ID that affects a product developed by Ozeki — matched by CVE ID, not by vendor name.