Skyworthdigital's vulnerability footprint centers on a focused line of set-top box and network media products, such as the CM5100 and RN510 models, which sit in consumer and small-business entertainment and streaming environments. A meaningful share of the vendor's disclosures reach serious severity, and the exposure recurs through weakness classes reflecting both web-application and low-level firmware concerns: cross-site scripting, cleartext transmission of sensitive information, cross-site request forgery, out-of-bounds writes, and classic buffer overflows. These patterns—particularly the combination of web-interface input-handling flaws and memory-safety issues in embedded firmware—are characteristic of devices that integrate legacy embedded code with modern web management interfaces, creating a broad attack surface for both local and remote compromise. Defenders inventorying these devices should prioritize access restrictions on management interfaces and firmware update coverage, as these products often remain in service long beyond active support cycles. Live exploitation activity and severity counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Skyworthdigital over time
Signals from CVEs in this vendor scope (31 CVEs).
31 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-19524CRITICAL An issue was discovered on Shenzhen Skyworth DT741 Converged Intelligent Terminal (G/EPON+IPTV) SDOTBGN1, DT721-cb SDOTBGN1, and DT741-cb SDOTBGN1 devices. A long password to the W | Mar 21, 2019 | 9.8 | 70 | NO | YES |
CVE-2018-20398CRITICAL Skyworth CM5100 V1.1.0, CM5100-440 V1.2.1, CM5100-511 4.1.0.14, CM5100-GHD00 V1.2.2, and CM5100.g2 4.1.0.17 devices allow remote attackers to discover credentials via iso.3.6.1.4.1 | Dec 23, 2018 | 9.8 | 31 | NO | NO |
CVE-2021-25328HIGH Skyworth Digital Technology RN510 V.3.1.0.4 RN510 V.3.1.0.4 contains a buffer overflow vulnerability in /cgi-bin/app-staticIP.asp. An authenticated attacker can send a specially cr | Apr 9, 2021 | 8.8 | 27 | NO | NO |
CVE-2021-41872HIGH Skyworth Digital Technology Penguin Aurora Box 41502 has a denial of service vulnerability, which can be exploited by attackers to cause a denial of service. | Oct 27, 2021 | 7.5 | 24 | NO | NO |
CVE-2023-51743HIGH This vulnerability exist in Skyworth Router CM5100, version 4.1.1.24, due to insufficient validation of user supplied input for the Set Upstream Channel ID (UCID) parameter at its | Jan 17, 2024 | 7.5 | 21 | NO | NO |
CVE-2023-51742HIGH This vulnerability exist in Skyworth Router CM5100, version 4.1.1.24, due to insufficient validation of user supplied input for the Add Downstream Frequency parameter at its web in | Jan 17, 2024 | 7.5 | 21 | NO | NO |
CVE-2023-51741HIGH This vulnerability exist in Skyworth Router CM5100, version 4.1.1.24, due to transmission of authentication credentials in plaintext over the network. A remote attacker could explo | Jan 17, 2024 | 7.5 | 21 | NO | NO |
CVE-2023-51740HIGH This vulnerability exist in Skyworth Router CM5100, version 4.1.1.24, due to transmission of authentication credentials in plaintext over the network. A remote attacker could explo | Jan 17, 2024 | 7.5 | 21 | NO | NO |
CVE-2021-25327MEDIUM Skyworth Digital Technology RN510 V.3.1.0.4 contains a cross-site request forgery (CSRF) vulnerability in /cgi-bin/net-routeadd.asp and /cgi-bin/sec-urlfilter.asp. Missing CSRF pro | Apr 9, 2021 | 6.5 | 20 | NO | NO |
CVE-2021-25326MEDIUM Skyworth Digital Technology RN510 V.3.1.0.4 is affected by an incorrect access control vulnerability in/cgi-bin/test_version.asp. If Wi-Fi is connected but an unauthenticated user | Apr 9, 2021 | 5.4 | 18 | NO | NO |
Signals from CVEs in this vendor scope (31 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Skyworthdigital.
Media articles that mention a CVE ID that affects a product developed by Skyworthdigital — matched by CVE ID, not by vendor name.