Saltos develops a modestly scoped portfolio of access-control and identity-management products, including the Rhinos and Saltos platforms, that manage authentication and authorization for physical and logical security systems. The vendor's vulnerabilities skew strongly toward critical-severity outcomes and frequently acquire public exploit code; they cluster around web-application and input-handling weakness classes including cross-site scripting, SQL injection, CSRF, code injection, and exposure of sensitive information—patterns consistent with the web-facing nature of authentication and identity platforms. Defenders should prioritize patches for this vendor's products, particularly where they are internet-reachable; live exploitation activity and severity counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Saltos over time
Signals from CVEs in this vendor scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-18761CRITICAL SaltOS 3.1 r8126 allows action=login&querystring=&user=[SQL] SQL Injection. | Nov 16, 2018 | 9.8 | 49 | NO | YES |
CVE-2018-18763CRITICAL SaltOS 3.1 r8126 allows action=ajax&query=numbers&page=usuarios&action2=[SQL] SQL Injection. | Nov 16, 2018 | 9.8 | 41 | NO | YES |
CVE-2018-18762MEDIUM SaltOS 3.1 r8126 contains a database download vulnerability. | Mar 21, 2019 | 6.5 | 32 | NO | YES |
CVE-2018-18760MEDIUM RhinOS 3.0 build 1190 allows CSRF. | Nov 16, 2018 | 6.5 | 32 | NO | YES |
CVE-2024-5407CRITICAL A vulnerability in RhinOS 3.0-1190 could allow PHP code injection through the "search" parameter in /portal/search.htm. This vulnerability could allow a remote attacker to perform | May 27, 2024 | 9.8 | 29 | NO | NO |
CVE-2024-5409MEDIUM RhinOS 3.0-1190 is vulnerable to an XSS via the "tamper" parameter in /admin/lib/phpthumb/phpthumb.php. An attacker could create a malicious URL and send it to a victim to obtain t | May 27, 2024 | 6.1 | 20 | NO | NO |
CVE-2024-5408MEDIUM Vulnerability in RhinOS 3.0-1190 consisting of an XSS through the "search" parameter of /portal/search.htm. This vulnerability could allow a remote attacker to steal details of a v | May 27, 2024 | 6.1 | 20 | NO | NO |
Signals from CVEs in this vendor scope (7 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Saltos.
Media articles that mention a CVE ID that affects a product developed by Saltos — matched by CVE ID, not by vendor name.