Piigab's vulnerability profile centers on the M-Bus 900S industrial communication device and its associated firmware, a narrowly scoped but strategically important product in the Industrial Internet of Things and metering infrastructure space. The exposure skews strongly toward critical-severity outcomes and clusters around web-application and authentication weaknesses—including cross-site request forgery, code injection, cross-site scripting, brute-force exposure, and plaintext credential storage—that are characteristic of embedded web interfaces with limited hardening. Defenders managing M-Bus 900S deployments should treat firmware updates as a high priority given the severity tendency; current exploitation and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Piigab over time
Signals from CVEs in this vendor scope (9 CVEs).
9 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-36859CRITICAL
PiiGAB M-Bus
SoftwarePack 900S
does not correctly sanitize user input, which could allow an attacker to inject arbitrary commands.
| Jul 6, 2023 | 9.8 | 30 | NO | NO |
CVE-2023-34995CRITICAL
There are no requirements for setting a complex password for PiiGAB M-Bus, which could contribute to a successful brute force attack if the password is inline with r | Jul 7, 2023 | 9.8 | 29 | NO | NO |
CVE-2023-34433CRITICAL
PiiGAB M-Bus stores passwords using a weak hash algorithm.
| Jul 7, 2023 | 9.8 | 26 | NO | NO |
CVE-2023-35120HIGH
PiiGAB M-Bus is vulnerable to cross-site request forgery. An attacker who wants to execute a certain command could send a phishing mail to the owner of the device and hope that th | Jul 7, 2023 | 8.8 | 24 | NO | NO |
CVE-2023-35987CRITICAL
PiiGAB M-Bus contains hard-coded credentials which it uses for authentication.
| Jul 6, 2023 | 9.8 | 24 | NO | NO |
CVE-2023-33868CRITICAL
The number of login attempts is not limited. This could allow an attacker to perform a brute force on HTTP basic authentication.
| Jul 6, 2023 | 9.8 | 24 | NO | NO |
CVE-2023-31277HIGH
PiiGAB M-Bus transmits credentials in plaintext format.
| Jul 6, 2023 | 7.5 | 21 | NO | NO |
CVE-2023-32652MEDIUM
PiiGAB M-Bus does not validate identification strings before processing, which could make it vulnerable to cross-site scripting attacks.
| Jul 7, 2023 | 6.1 | 20 | NO | NO |
CVE-2023-35765MEDIUM
PiiGAB M-Bus stores credentials in a plaintext file, which could allow a low-level user to gain admin credentials.
| Jul 7, 2023 | 6.5 | 17 | NO | NO |
Signals from CVEs in this vendor scope (9 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Piigab.
Media articles that mention a CVE ID that affects a product developed by Piigab — matched by CVE ID, not by vendor name.