Rangee develops RangeeOS, a narrowly scoped embedded or networked product with a durable signal centered on command-injection vulnerabilities and output-encoding issues that arise in systems processing untrusted input. The recurrence of OS command injection, improper output escaping, and credential-protection gaps reflects common weaknesses in products that parse user-supplied data or manage authentication material. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Rangee over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-16279CRITICAL The Kommbox component in Rangee GmbH RangeeOS 8.0.4 is vulnerable to Remote Code Execution due to untrusted user supplied input being passed to the command line without sanitizatio | Aug 20, 2020 | 9.8 | 30 | NO | NO |
CVE-2020-16282HIGH In the default configuration of Rangee GmbH RangeeOS 8.0.4, all components are executed in the context of the privileged root user. This may allow a local attacker to break out of | Aug 20, 2020 | 8.8 | 27 | NO | NO |
CVE-2020-16281HIGH The Kommbox component in Rangee GmbH RangeeOS 8.0.4 could allow a local authenticated attacker to escape from the restricted environment and execute arbitrary code due to unrestric | Aug 20, 2020 | 7.8 | 20 | NO | NO |
CVE-2020-16280MEDIUM Multiple Rangee GmbH RangeeOS 8.0.4 modules store credentials in plaintext including credentials of users for several external facing administrative services, domain joined users, | Aug 20, 2020 | 5.5 | 19 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Rangee.
Media articles that mention a CVE ID that affects a product developed by Rangee — matched by CVE ID, not by vendor name.