Raisecom manufactures a focused line of messaging and telecom gateway appliances, particularly the MSG series, that serve as network infrastructure for voice and data integration in enterprise and carrier environments. Vulnerabilities affecting the vendor skew strongly toward critical-severity outcomes and frequently acquire public exploit tooling, concentrating in firmware across its gateway platforms through weakness classes including OS command injection, path traversal, and unrestricted file upload that are characteristic of management interfaces in embedded systems. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Raisecom over time
Signals from CVEs in this vendor scope (11 CVEs).
11 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-7120CRITICAL A vulnerability, which was classified as critical, was found in Raisecom MSG1200, MSG2100E, MSG2200 and MSG2300 3.90. This affects an unknown part of the file list_base_config.php | Jul 26, 2024 | 9.8 | 87 | NO | YES |
CVE-2024-7470CRITICAL A vulnerability was found in Raisecom MSG1200, MSG2100E, MSG2200 and MSG2300 3.90. It has been rated as critical. This issue affects the function sslvpn_config_mod of the file /vpn | Aug 5, 2024 | 9.8 | 42 | NO | NO |
CVE-2024-7469CRITICAL A vulnerability was found in Raisecom MSG1200, MSG2100E, MSG2200 and MSG2300 3.90. It has been declared as critical. This vulnerability affects the function sslvpn_config_mod of th | Aug 5, 2024 | 9.8 | 42 | NO | NO |
CVE-2024-7468CRITICAL A vulnerability was found in Raisecom MSG1200, MSG2100E, MSG2200 and MSG2300 3.90. It has been classified as critical. This affects the function sslvpn_config_mod of the file /vpn/ | Aug 5, 2024 | 9.8 | 42 | NO | NO |
CVE-2024-7467CRITICAL A vulnerability was found in Raisecom MSG1200, MSG2100E, MSG2200 and MSG2300 3.90 and classified as critical. Affected by this issue is the function sslvpn_config_mod of the file / | Aug 5, 2024 | 9.8 | 41 | NO | NO |
CVE-2019-7385HIGH An authenticated shell command injection issue has been discovered in Raisecom ISCOM HT803G-U, HT803G-W, HT803G-1GE, and HT803G GPON products with the firmware version ISCOMHT803G- | Mar 21, 2019 | 7.8 | 36 | NO | YES |
CVE-2019-7384HIGH An authenticated shell command injection issue has been discovered in Raisecom ISCOM HT803G-U, HT803G-W, HT803G-1GE, and HT803G GPON products with the firmware version ISCOMHT803G- | Mar 21, 2019 | 7.8 | 27 | NO | NO |
CVE-2024-55515CRITICAL A vulnerability was found in Raisecom MSG1200, MSG2100E, MSG2200, and MSG2300 3.90. The component affected by this issue is /upload_ipslib.php on the web interface. By crafting a s | Dec 17, 2024 | 9.8 | 26 | NO | NO |
CVE-2024-55516CRITICAL A vulnerability was found in Raisecom MSG1200, MSG2100E, MSG2200, and MSG2300 v3.90. The component affected by this issue is /upload_sysconfig.php on the web interface. By crafting | Dec 17, 2024 | 9.1 | 24 | NO | NO |
CVE-2024-55513CRITICAL A vulnerability was found in Raisecom MSG1200, MSG2100E, MSG2200, and MSG2300 3.90. The component affected by this issue is /upload_netaction.php on the web interface. By crafting | Dec 17, 2024 | 9.1 | 24 | NO | NO |
Signals from CVEs in this vendor scope (11 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Raisecom.
Media articles that mention a CVE ID that affects a product developed by Raisecom — matched by CVE ID, not by vendor name.