Rifartek develops IoT wall control and automation products that manage building systems and environmental conditions through networked interfaces, presenting a focused but potentially widely distributed embedded footprint. Disclosed vulnerabilities center on input-handling and access-control weaknesses typical of web-facing control interfaces, including cross-site scripting and improper authorization flaws that could allow unauthorized command execution or control manipulation. Current exploitation activity, severity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Rifartek over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-25017HIGH RIFARTEK IOT Wall has a vulnerability of incorrect authorization. An authenticated remote attacker with general user privilege is allowed to perform specific privileged function to | Mar 27, 2023 | 8.1 | 24 | NO | NO |
CVE-2023-25018MEDIUM RIFARTEK IOT Wall transportation function has insufficient filtering for user input. An authenticated remote attacker with general user privilege can inject JavaScript to perform r | Mar 27, 2023 | 5.4 | 19 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Rifartek.
Media articles that mention a CVE ID that affects a product developed by Rifartek — matched by CVE ID, not by vendor name.