Relyum's vulnerability footprint centers on a narrow portfolio of PCIe-based hardware and firmware products, which despite limited product breadth occupy a more prominent position in the landscape than typical for this vendor class. The exposure recurs through weakness classes characteristic of embedded systems and hardware interfaces—command injection, improper access control, cross-site scripting, and CSRF—reflecting the interaction between firmware, web-based management interfaces, and privileged hardware access. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Relyum over time
Signals from CVEs in this vendor scope (14 CVEs).
14 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-47577CRITICAL An issue discovered in Relyum RELY-PCIe 22.2.1 and RELY-REC 23.1.0 allows for unauthorized password changes due to no check for current password. | Dec 13, 2023 | 9.8 | 30 | NO | NO |
CVE-2024-44577HIGH RELY-PCIe v22.2.1 to v23.1.0 was discovered to contain a command injection vulnerability via the time_date function. | Sep 11, 2024 | 8.8 | 26 | NO | NO |
CVE-2024-44574HIGH RELY-PCIe v22.2.1 to v23.1.0 was discovered to contain a command injection vulnerability via the sys_conf function. | Sep 11, 2024 | 8.8 | 26 | NO | NO |
CVE-2024-44572HIGH RELY-PCIe v22.2.1 to v23.1.0 was discovered to contain a command injection vulnerability via the sys_mgmt function. | Sep 11, 2024 | 8.8 | 26 | NO | NO |
CVE-2024-44571HIGH RELY-PCIe v22.2.1 to v23.1.0 was discovered to contain incorrect access control in the mService function at phpinf.php. | Sep 11, 2024 | 8.8 | 26 | NO | NO |
CVE-2024-44570HIGH RELY-PCIe v22.2.1 to v23.1.0 was discovered to contain a code injection vulnerability via the getParams function in phpinf.php. | Sep 11, 2024 | 8.8 | 26 | NO | NO |
CVE-2023-47578HIGH Relyum RELY-PCIe 22.2.1 and RELY-REC 23.1.0 devices are susceptible to Cross Site Request Forgery (CSRF) attacks due to the absence of CSRF protection in the web interface. | Dec 13, 2023 | 8.8 | 23 | NO | NO |
CVE-2023-47576HIGH An issue was discovered in Relyum RELY-PCIe 22.2.1 and RELY-REC 23.1.0 devices, allowing authenticated command injection through the web interface. | Dec 13, 2023 | 8.8 | 23 | NO | NO |
CVE-2023-47573HIGH An issue discovered in Relyum RELY-PCIe 22.2.1 devices. The authorization mechanism is not enforced in the web interface, allowing a low-privileged user to execute administrative f | Dec 13, 2023 | 8.8 | 23 | NO | NO |
CVE-2023-47579HIGH Relyum RELY-PCIe 22.2.1 devices suffer from a system group misconfiguration, allowing read access to the central password hash file of the operating system. | Dec 13, 2023 | 7.5 | 20 | NO | NO |
Signals from CVEs in this vendor scope (14 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Relyum.
Media articles that mention a CVE ID that affects a product developed by Relyum — matched by CVE ID, not by vendor name.