Seiko Sol's vulnerability profile centers on a narrow line of SkyBridge managed backbone appliances spanning model variants from the A100 through A200 series, alongside their associated firmware components. These are specialized network infrastructure devices that sit at the backbone level of enterprise environments, presenting a focused but strategically positioned attack surface for defenders tracking this vendor's advisories. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Seiko Sol over time
Signals from CVEs in this vendor scope (14 CVEs).
14 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-22361MEDIUM Improper privilege management vulnerability in SkyBridge MB-A100/110 firmware Ver. 4.2.0 and earlier allows a remote authenticated attacker to alter a WebUI password of the product | May 10, 2023 | 6.5 | 40 | NO | NO |
CVE-2022-36556CRITICAL Seiko SkyBridge MB-A100/A110 v4.2.0 and below was discovered to contain a command injection vulnerability via the ipAddress parameter at 07system08execute_ping_01. | Aug 29, 2022 | 9.8 | 32 | NO | NO |
CVE-2022-36559CRITICAL Seiko SkyBridge MB-A200 v01.00.04 and below was discovered to contain a command injection vulnerability via the Ping parameter at ping_exec.cgi. | Aug 29, 2022 | 9.8 | 31 | NO | NO |
CVE-2022-36558CRITICAL Seiko SkyBridge MB-A100/A110 v4.2.0 and below implements a hard-coded passcode for the root account. Attackers are able to access the passcord via the file /etc/ciel.cfg. | Aug 29, 2022 | 9.8 | 31 | NO | NO |
CVE-2022-36557CRITICAL Seiko SkyBridge MB-A100/A110 v4.2.0 and below was discovered to contain an arbitrary file upload vulnerability via the restore backup function. This vulnerability allows attackers | Aug 29, 2022 | 9.8 | 31 | NO | NO |
CVE-2022-36560CRITICAL Seiko SkyBridge MB-A200 v01.00.04 and below was discovered to contain multiple hard-coded passcodes for root. Attackers are able to access the passcodes at /etc/srapi/config/system | Aug 29, 2022 | 9.8 | 30 | NO | NO |
CVE-2023-22441HIGH Missing authentication for critical function exists in Seiko Solutions SkyBridge series, which may allow a remote attacker to obtain or alter the setting information of the product | May 10, 2023 | 8.6 | 27 | NO | NO |
CVE-2023-25072HIGH Use of weak credentials exists in SkyBridge MB-A100/110 firmware Ver. 4.2.0 and earlier, which may allow a remote unauthenticated attacker to decrypt password for the WebUI of the | May 10, 2023 | 7.5 | 25 | NO | NO |
CVE-2023-23578HIGH Improper access control vulnerability in SkyBridge MB-A200 firmware Ver. 01.00.05 and earlier allows a remote unauthenticated attacker to connect to the product's ADB port. | May 10, 2023 | 7.5 | 24 | NO | NO |
CVE-2023-25070MEDIUM Cleartext transmission of sensitive information exists in SkyBridge MB-A100/110 firmware Ver. 4.2.0 and earlier. If the telnet connection is enabled, a remote unauthenticated attac | May 10, 2023 | 6.5 | 23 | NO | NO |
Signals from CVEs in this vendor scope (14 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Seiko Sol.
Media articles that mention a CVE ID that affects a product developed by Seiko Sol — matched by CVE ID, not by vendor name.