Radixiot develops IoT and industrial automation platforms, particularly its Mango and MangoAPI products, which present a web-facing attack surface centered on remote monitoring and control capabilities. The durable signal across disclosures centers on input-handling and code-execution weaknesses—code injection, path traversal, cross-site scripting, OS command injection, and unrestricted file upload—that are characteristic of web application integration in operational-technology environments. Current severity, exploitation, and exposure metrics are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Radixiot over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-37847HIGH An arbitrary file upload vulnerability in MangoOS before 5.1.4 and Mango API before 4.5.5 allows attackers to execute arbitrary code via a crafted file. | Oct 25, 2024 | 8.8 | 25 | NO | NO |
CVE-2024-37845HIGH MangoOS before 5.2.0 was discovered to contain an authenticated remote code execution (RCE) vulnerability via the Active Process Command feature. | Oct 25, 2024 | 7.2 | 21 | NO | NO |
CVE-2024-37846MEDIUM MangoOS before 5.2.0 was discovered to contain a Client-Side Template Injection (CSTI) vulnerability via the Platform Management Edit page. | Oct 25, 2024 | 4.6 | 18 | NO | NO |
CVE-2024-37844MEDIUM A stored cross-site scripting (XSS) vulnerability in MangoOS before 5.2.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload. | Oct 25, 2024 | 5.4 | 17 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Radixiot.
Media articles that mention a CVE ID that affects a product developed by Radixiot — matched by CVE ID, not by vendor name.