Sensaphone manufactures remote-monitoring and notification products, particularly its Web600 environmental monitoring appliance, with a narrow but specialized focus on facility and infrastructure supervision. The durable signal centers on web-facing input-handling weaknesses, specifically cross-site scripting vulnerabilities in the device's web interface, reflecting the attack surface inherent to embedded monitoring devices with browser-based management. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Sensaphone over time
Signals from CVEs in this vendor scope (1 CVEs).
1 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-55040MEDIUM Cross Site Scripting vulnerability in Sensaphone WEB600 Monitoring System v.1.6.5.H and before allows a remote attacker to execute arbitrary code via a crafted GET requests to /@.x | Jul 21, 2025 | 6.1 | 18 | NO | NO |
Signals from CVEs in this vendor scope (1 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Sensaphone.
Media articles that mention a CVE ID that affects a product developed by Sensaphone — matched by CVE ID, not by vendor name.