Paradox manufactures access-control and security systems centered on networked intrusion panels and firmware such as the IP150 and IPR512, products often deployed in physical security infrastructure. The recurring vulnerability pattern reflects buffer-handling and code-injection weaknesses endemic to embedded firmware, where input validation and memory safety are persistent implementation challenges. Current severity, exploitation activity, and exposure metrics are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Paradox over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-24709HIGH An issue found in Paradox Security Systems IPR512 allows attackers to cause a denial of service via the login.html and login.xml parameters. | Mar 21, 2023 | 7.5 | 52 | NO | YES |
CVE-2020-25189CRITICAL The affected product is vulnerable to three stack-based buffer overflows, which may allow an unauthenticated attacker to remotely execute arbitrary code on the IP150 (firmware vers | Nov 21, 2020 | 9.8 | 30 | NO | NO |
CVE-2020-25185HIGH The affected product is vulnerable to five post-authentication buffer overflows, which may allow a logged in user to remotely execute arbitrary code on the IP150 (firmware versions | Nov 21, 2020 | 8.8 | 28 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Paradox.
Media articles that mention a CVE ID that affects a product developed by Paradox — matched by CVE ID, not by vendor name.