Rad's vulnerability profile centers on the SecFlow-1V appliance and its firmware, a narrowly scoped product line where the durable signal reflects application-layer input-handling and file-upload weaknesses typical of web-facing management interfaces, including cross-site request forgery, cross-site scripting, and unrestricted file uploads. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Rad over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-13259HIGH A vulnerability in the web-based management interface of RAD SecFlow-1v os-image SF_0290_2.3.01.26 could allow an unauthenticated, remote attacker to conduct a cross-site request f | Sep 16, 2020 | 8.8 | 39 | NO | YES |
CVE-2020-13260MEDIUM A vulnerability in the web-based management interface of RAD SecFlow-1v through 2020-05-21 could allow an authenticated attacker to upload a JavaScript file, with a stored XSS payl | Sep 17, 2020 | 6.1 | 25 | NO | YES |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Rad.
Media articles that mention a CVE ID that affects a product developed by Rad — matched by CVE ID, not by vendor name.