Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Skyworthdigital

First CVE: Dec 23, 2018Active for: 8 yearsTotal CVEs: 31
25.2
VTI Score
Low

Skyworthdigital's vulnerability footprint centers on a focused line of set-top box and network media products, such as the CM5100 and RN510 models, which sit in consumer and small-business entertainment and streaming environments. A meaningful share of the vendor's disclosures reach serious severity, and the exposure recurs through weakness classes reflecting both web-application and low-level firmware concerns: cross-site scripting, cleartext transmission of sensitive information, cross-site request forgery, out-of-bounds writes, and classic buffer overflows. These patterns—particularly the combination of web-interface input-handling flaws and memory-safety issues in embedded firmware—are characteristic of devices that integrate legacy embedded code with modern web management interfaces, creating a broad attack surface for both local and remote compromise. Defenders inventorying these devices should prioritize access restrictions on management interfaces and firmware update coverage, as these products often remain in service long beyond active support cycles. Live exploitation activity and severity counts are shown alongside this summary.

FAUCET AI Generated
31
Total CVEs
More Total CVEs than 97% of tracked vendors
0.4
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 4% of tracked vendors
6.2
Avg CVSS Score
Higher Avg CVSS Score than 35% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Skyworthdigital over time

Volume of CVEsAvg CVSS Base Score
First CVE
Dec 23, 2018
7 years ago
Most Recent CVE
Jan 17, 2024
920 days ago

Products(20 total)

Top CVEs

Signals from CVEs in this vendor scope (31 CVEs).

31 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2018-19524CRITICAL
An issue was discovered on Shenzhen Skyworth DT741 Converged Intelligent Terminal (G/EPON+IPTV) SDOTBGN1, DT721-cb SDOTBGN1, and DT741-cb SDOTBGN1 devices. A long password to the W
Mar 21, 20199.870NOYES
CVE-2018-20398CRITICAL
Skyworth CM5100 V1.1.0, CM5100-440 V1.2.1, CM5100-511 4.1.0.14, CM5100-GHD00 V1.2.2, and CM5100.g2 4.1.0.17 devices allow remote attackers to discover credentials via iso.3.6.1.4.1
Dec 23, 20189.831NONO
CVE-2021-25328HIGH
Skyworth Digital Technology RN510 V.3.1.0.4 RN510 V.3.1.0.4 contains a buffer overflow vulnerability in /cgi-bin/app-staticIP.asp. An authenticated attacker can send a specially cr
Apr 9, 20218.827NONO
CVE-2021-41872HIGH
Skyworth Digital Technology Penguin Aurora Box 41502 has a denial of service vulnerability, which can be exploited by attackers to cause a denial of service.
Oct 27, 20217.524NONO
CVE-2023-51743HIGH
This vulnerability exist in Skyworth Router CM5100, version 4.1.1.24, due to insufficient validation of user supplied input for the Set Upstream Channel ID (UCID) parameter at its
Jan 17, 20247.521NONO
CVE-2023-51742HIGH
This vulnerability exist in Skyworth Router CM5100, version 4.1.1.24, due to insufficient validation of user supplied input for the Add Downstream Frequency parameter at its web in
Jan 17, 20247.521NONO
CVE-2023-51741HIGH
This vulnerability exist in Skyworth Router CM5100, version 4.1.1.24, due to transmission of authentication credentials in plaintext over the network. A remote attacker could explo
Jan 17, 20247.521NONO
CVE-2023-51740HIGH
This vulnerability exist in Skyworth Router CM5100, version 4.1.1.24, due to transmission of authentication credentials in plaintext over the network. A remote attacker could explo
Jan 17, 20247.521NONO
CVE-2021-25327MEDIUM
Skyworth Digital Technology RN510 V.3.1.0.4 contains a cross-site request forgery (CSRF) vulnerability in /cgi-bin/net-routeadd.asp and /cgi-bin/sec-urlfilter.asp. Missing CSRF pro
Apr 9, 20216.520NONO
CVE-2021-25326MEDIUM
Skyworth Digital Technology RN510 V.3.1.0.4 is affected by an incorrect access control vulnerability in/cgi-bin/test_version.asp. If Wi-Fi is connected but an unauthenticated user
Apr 9, 20215.418NONO
View all 31 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products31 CVEs
74%
19%
Severity distribution among all CVEs352,427 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network31 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low31 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None8 (25.8%)
Unknown0 (0.0%)
Required23 (74.2%)
Privileges Required
Low23 (74.2%)
High0 (0.0%)
None8 (25.8%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (31 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
1 CVE
3.2% of CVEs· 75th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Skyworthdigital.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Skyworthdigital — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Skyworthdigital's Products

View all 2 CNAs →

Top CWEs