Sewio develops real-time location system software that enables indoor positioning and asset tracking, a niche but strategically important class of infrastructure. Its vulnerability profile concentrates in a single product line and skews toward critical-severity outcomes, with recurring weaknesses spanning web-layer input-handling issues such as cross-site scripting and OS command injection alongside out-of-bounds writes that suggest deeper memory-safety concerns. Defenders deploying this tracking infrastructure should treat vendor advisories as high-priority; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Sewio over time
Signals from CVEs in this vendor scope (9 CVEs).
9 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-45444CRITICAL Sewio’s Real-Time Location System (RTLS) Studio version 2.0.0 up to and including version 2.6.2 contains hard-coded passwords for select users in the application’s database. This c | Jan 18, 2023 | 9.8 | 31 | NO | NO |
CVE-2022-41989CRITICAL Sewio’s Real-Time Location System (RTLS) Studio version 2.0.0 up to and including version 2.6.2 does not validate the length of RTLS report payloads during communication. This allo | Jan 18, 2023 | 9.8 | 30 | NO | NO |
CVE-2022-45127HIGH Sewio’s Real-Time Location System (RTLS) Studio version 2.0.0 up to and including version 2.6.2 is vulnerable to cross-site request forgery in its backup services. An attacker coul | Jan 18, 2023 | 8.1 | 26 | NO | NO |
CVE-2022-47395HIGH Sewio’s Real-Time Location System (RTLS) Studio version 2.0.0 up to and including version 2.6.2 is vulnerable to cross-site request forgery in its monitor services. An attacker cou | Jan 18, 2023 | 8.1 | 25 | NO | NO |
CVE-2022-43483HIGH Sewio’s Real-Time Location System (RTLS) Studio version 2.0.0 up to and including version 2.6.2 does not properly validate the input module name to the monitor services of the soft | Jan 18, 2023 | 7.2 | 25 | NO | NO |
CVE-2022-47911HIGH Sewio’s Real-Time Location System (RTLS) Studio version 2.0.0 up to and including version 2.6.2 does not properly validate the input module name to the backup services of the softw | Jan 18, 2023 | 7.2 | 24 | NO | NO |
CVE-2022-46733CRITICAL Sewio’s Real-Time Location System (RTLS) Studio version 2.0.0 up to and including version 2.6.2 is vulnerable to cross-site scripting in its backup services. An attacker could take | Jan 18, 2023 | 9.6 | 23 | NO | NO |
CVE-2022-43455MEDIUM Sewio’s Real-Time Location System (RTLS) Studio version 2.0.0 up to and including version 2.6.2 is vulnerable to improper input validation of user input to the service_start, servi | Jan 18, 2023 | 6.5 | 23 | NO | NO |
CVE-2022-47917MEDIUM Sewio’s Real-Time Location System (RTLS) Studio version 2.0.0 up to and including version 2.6.2 is vulnerable to improper input validation of user input to several modules and serv | Jan 18, 2023 | 6.5 | 22 | NO | NO |
Signals from CVEs in this vendor scope (9 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Sewio.
Media articles that mention a CVE ID that affects a product developed by Sewio — matched by CVE ID, not by vendor name.