Seekswan's vulnerability footprint centers on its ZikeStor SKS8310 network storage appliance and associated firmware, a specialized embedded device. The recurring weakness classes—cross-site scripting, OS command injection, missing authentication for critical functions, and insufficient random-value generation—reflect common input-handling and access-control gaps in web-facing storage management interfaces. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Seekswan over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-25072CRITICAL XikeStor SKS8310-8X Network Switch firmware versions 1.04.B07 and prior contain a predictable session identifier vulnerability in the /goform/SetLogin endpoint that allows remote a | Mar 7, 2026 | 9.8 | 31 | NO | NO |
CVE-2026-25070CRITICAL XikeStor SKS8310-8X Network Switch firmware versions 1.04.B07 and prior contain an OS command injection vulnerability in the /goform/PingTestSet endpoint that allows unauthenticate | Mar 7, 2026 | 9.8 | 31 | NO | NO |
CVE-2026-25071HIGH XikeStor SKS8310-8X Network Switch firmware versions 1.04.B07 and prior contain a missing authentication vulnerability in the /switch_config.src endpoint that allows unauthenticate | Mar 7, 2026 | 7.5 | 26 | NO | NO |
CVE-2026-25073MEDIUM XikeStor SKS8310-8X Network Switch firmware versions 1.04.B07 and prior contain a stored cross-site scripting vulnerability that allows authenticated attackers to inject arbitrary | Mar 7, 2026 | 5.4 | 21 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Seekswan.
Media articles that mention a CVE ID that affects a product developed by Seekswan — matched by CVE ID, not by vendor name.