Robustel manufactures a narrow line of industrial and mobile cellular routers, prominently the R1510 series, that provide connectivity and remote-management capabilities in field deployment contexts where device hardening and timely patching cycles are often constrained. The vendor's vulnerability profile concentrates in its firmware implementations and skews strongly toward critical-severity outcomes, reflecting the memory-safety and command-injection risks inherent to embedded systems with extensive OS-level access. Recurring weakness classes include OS command injection, command injection, path traversal, out-of-bounds reads, and active debug code—a pattern typical of industrial networking appliances where legacy code, administrative interfaces, and direct system calls create a broad attack surface. The R1510 router's role as a gateway device with remote-access capabilities amplifies the impact of these flaws for operators in sectors such as utilities and transportation. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Robustel over time
Signals from CVEs in this vendor scope (26 CVEs).
26 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-28127CRITICAL A data removal vulnerability exists in the web_server /action/remove/ API functionality of Robustel R1510 3.3.0. A specially-crafted network request can lead to arbitrary file dele | Jun 30, 2022 | 9.1 | 46 | NO | NO |
CVE-2022-33312CRITICAL Multiple command injection vulnerabilities exist in the web_server action endpoints functionalities of Robustel R1510 3.3.0. A specially-crafted network request can lead to arbitra | Jun 30, 2022 | 9.8 | 33 | NO | NO |
CVE-2022-33329CRITICAL Multiple command injection vulnerabilities exist in the web_server ajax endpoints functionalities of Robustel R1510 3.3.0. A specially-crafted network packets can lead to arbitrary | Jun 30, 2022 | 9.8 | 32 | NO | NO |
CVE-2022-33328CRITICAL Multiple command injection vulnerabilities exist in the web_server ajax endpoints functionalities of Robustel R1510 3.3.0. A specially-crafted network packets can lead to arbitrary | Jun 30, 2022 | 9.8 | 32 | NO | NO |
CVE-2022-33327CRITICAL Multiple command injection vulnerabilities exist in the web_server ajax endpoints functionalities of Robustel R1510 3.3.0. A specially-crafted network packets can lead to arbitrary | Jun 30, 2022 | 9.8 | 32 | NO | NO |
CVE-2022-33325CRITICAL Multiple command injection vulnerabilities exist in the web_server ajax endpoints functionalities of Robustel R1510 3.3.0. A specially-crafted network packets can lead to arbitrary | Jun 30, 2022 | 9.8 | 32 | NO | NO |
CVE-2022-32585CRITICAL A command execution vulnerability exists in the clish art2 functionality of Robustel R1510 3.3.0. A specially-crafted network request can lead to arbitrary command execution. An at | Jun 30, 2022 | 9.8 | 32 | NO | NO |
CVE-2022-33314CRITICAL Multiple command injection vulnerabilities exist in the web_server action endpoints functionalities of Robustel R1510 3.3.0. A specially-crafted network request can lead to arbitra | Jun 30, 2022 | 9.8 | 31 | NO | NO |
CVE-2022-32765CRITICAL An OS command injection vulnerability exists in the sysupgrade command injection functionality of Robustel R1510 3.1.16 and 3.3.0. A specially-crafted network request can lead to a | Oct 25, 2022 | 9.8 | 30 | NO | NO |
CVE-2022-33897CRITICAL A directory traversal vulnerability exists in the web_server /ajax/remove/ functionality of Robustel R1510 3.1.16. A specially-crafted network request can lead to arbitrary file de | Oct 25, 2022 | 9.1 | 29 | NO | NO |
Signals from CVEs in this vendor scope (26 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Robustel.
Media articles that mention a CVE ID that affects a product developed by Robustel — matched by CVE ID, not by vendor name.