Resi's vulnerability footprint centers on Gemini-Net, a narrowly scoped networking product, with the recurring signal reflecting application input-handling weaknesses including cross-site scripting, OS command injection, and other input-neutralization issues. Treat this as a compact vendor profile rather than a broad trend line; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Resi over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-29539CRITICAL resi-calltrace in RESI Gemini-Net 4.2 is affected by OS Command Injection. It does not properly check the parameters sent as input before they are processed on the server. Due to t | May 12, 2022 | 9.8 | 31 | NO | NO |
CVE-2022-29540MEDIUM resi-calltrace in RESI Gemini-Net 4.2 is affected by Multiple XSS issues. Unauthenticated remote attackers can inject arbitrary web script or HTML into an HTTP GET parameter that r | Jun 2, 2022 | 6.1 | 20 | NO | NO |
CVE-2022-29538MEDIUM RESI Gemini-Net Web 4.2 is affected by Improper Access Control in authorization logic. An unauthenticated user is able to access some critical resources. | May 12, 2022 | 5.3 | 20 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Resi.
Media articles that mention a CVE ID that affects a product developed by Resi — matched by CVE ID, not by vendor name.