Panasonic's vulnerability footprint spans industrial automation, building management, and networked appliance products, with particular concentration in programmable logic controller (PLC) software such as FPWIN Pro and network-connected broadcast and storage devices. The exposure recurs through memory-safety and input-handling weakness classes including buffer overflows, out-of-bounds writes, improper input validation, and SQL injection, reflecting the firmware and legacy-codebase demands of embedded and operational-technology contexts. A meaningful share of these vulnerabilities reach critical severity, typical of memory-unsafe or unauthenticated access patterns in systems where available defensive tooling is limited. Defenders should prioritize inventory and air-gapping of these industrial and broadcast devices, particularly older firmware versions, and track Panasonic's advisories closely where products sit in networked control environments. Current exploitation activity and severity distribution are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Panasonic over time
Signals from CVEs in this vendor scope (42 CVEs).
42 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-5997CRITICAL Video Insight VMS versions prior to 7.6.1 allow remote attackers to conduct code injection attacks via unspecified vectors. | May 20, 2020 | 9.8 | 31 | NO | NO |
CVE-2020-11715CRITICAL Panasonic P99 devices through 2020-04-10 have Incorrect Access Control. NOTE: the vendor states that all affected products are at "End-of-software-support." | May 19, 2020 | 9.8 | 30 | NO | NO |
CVE-2021-20623CRITICAL Video Insight VMS versions prior to 7.8 allows a remote attacker to execute arbitrary code with the system user privilege by sending a specially crafted request. | Feb 5, 2021 | 9.8 | 29 | NO | NO |
CVE-2020-11716CRITICAL Panasonic P110, Eluga Z1 Pro, Eluga X1, and Eluga X1 Pro devices through 2020-04-10 have Insecure Permissions. NOTE: the vendor states that all affected products are at "End-of-sof | May 20, 2020 | 9.8 | 29 | NO | NO |
CVE-2023-28727HIGH Panasonic AiSEG2 versions 2.00J through 2.93A allows adjacent attackers bypass authentication due to mishandling of X-Forwarded-For headers. | Mar 31, 2023 | 8.8 | 28 | NO | NO |
CVE-2023-28726HIGH Panasonic AiSEG2 versions 2.80F through 2.93A allows remote attackers to execute arbitrary OS commands. | Mar 31, 2023 | 8.8 | 28 | NO | NO |
CVE-2022-4621HIGH Panasonic Sanyo CCTV Network Cameras versions 1.02-05 and 2.03-0x are
vulnerable to CSRFs that can be exploited to allow an attacker to
perform changes with administrator level p | Jan 17, 2023 | 8.8 | 28 | NO | NO |
CVE-2018-0676HIGH BN-SDWBP3 firmware version 1.0.9 and earlier allows an attacker on the same network segment to bypass authentication to access to the management screen and execute an arbitrary com | Jan 9, 2019 | 8.8 | 28 | NO | NO |
CVE-2017-2133HIGH SQL injection vulnerability in Panasonic KX-HJB1000 Home unit devices with firmware GHX1YG 14.50 or HJB1000_4.47 allows authenticated attackers to execute arbitrary SQL commands vi | Oct 20, 2017 | 8.8 | 28 | NO | NO |
CVE-2019-5996HIGH SQL injection vulnerability in the Video Insight VMS 7.3.2.5 and earlier allows remote authenticated attackers to execute arbitrary SQL commands via unspecified vectors. | Sep 12, 2019 | 8.8 | 27 | NO | NO |
Signals from CVEs in this vendor scope (42 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Panasonic.
Media articles that mention a CVE ID that affects a product developed by Panasonic — matched by CVE ID, not by vendor name.