Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Soliton

First CVE: Nov 15, 2018Active for: 8 yearsTotal CVEs: 7

Soliton develops a focused portfolio of remote-access, secure-browsing, and endpoint-protection products including FileZen, SecureBrowser variants, and SecureWorkspace that serve Japanese enterprise and government sectors. Its vulnerability profile skews strongly toward critical severity and carries an elevated tendency toward confirmed in-the-wild exploitation, clustering around OS command injection, path traversal, and authorization weaknesses that are characteristic of privileged software with direct system access. Defenders should treat this vendor's advisories as high-priority for exposed instances; live severity and exploitation figures are shown alongside this summary.

FAUCET AI Generated
7
Total CVEs
More Total CVEs than 88% of tracked vendors
0.2
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 1% of tracked vendors
7.6
Avg CVSS Score
Higher Avg CVSS Score than 72% of tracked vendors
14.3%
In CISA KEV
Higher KEV Rate than 100% of tracked vendors

Trends Over Time

The number and severity of CVEs published that impact products developed by Soliton over time

Volume of CVEsAvg CVSS Base Score
First CVE
Nov 15, 2018
7 years ago
Most Recent CVE
Feb 27, 2026
148 days ago

Products(7 total)

Top CVEs

Signals from CVEs in this vendor scope (7 CVEs).

7 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2026-25108HIGH
FileZen contains an OS command injection vulnerability. When FileZen Antivirus Check Option is enabled, a logged-in user may send a specially crafted HTTP request to execute an arb
Feb 13, 20268.874YESNO
CVE-2018-0694CRITICAL
FileZen V3.0.0 to V4.2.1 allows remote attackers to execute arbitrary OS commands via unspecified vectors.
Nov 15, 20189.832NONO
CVE-2020-5639CRITICAL
Directory traversal vulnerability in FileZen versions from V3.0.0 to V4.2.2 allows remote attackers to upload an arbitrary file in a specific directory via unspecified vectors. As
Dec 14, 20209.826NONO
CVE-2021-20655HIGH
FileZen (V3.0.0 to V4.2.7 and V5.0.0 to V5.0.2) allows a remote attacker with administrator rights to execute arbitrary OS commands via unspecified vectors.
Feb 17, 20217.225NONO
CVE-2018-0693HIGH
Directory traversal vulnerability in FileZen V3.0.0 to V4.2.1 allows remote attackers to upload an arbitrary file in the specific directory in FileZen via unspecified vectors.
Nov 15, 20187.525NONO
CVE-2026-27653MEDIUM
The installers for multiple products provided by Soliton Systems K.K. contain an issue with incorrect default permissions, which may allow arbitrary code to be executed with SYSTEM
Feb 27, 20266.723NONO
CVE-2023-39341LOW
"FFRI yarai", "FFRI yarai Home and Business Edition" and their OEM products handle exceptional conditions improperly, which may lead to denial-of-service (DoS) condition. Affecte
Aug 9, 20233.314NONO
View all 7 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products7 CVEs
14%
14%
43%
29%
Severity distribution among all CVEs352,427 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local2 (28.6%)
Network5 (71.4%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low6 (85.7%)
High1 (14.3%)
Unknown0 (0.0%)
User Interaction
None5 (71.4%)
Unknown0 (0.0%)
Required2 (28.6%)
Privileges Required
Low2 (28.6%)
High1 (14.3%)
None4 (57.1%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (7 CVEs).

CISA KEV
1 CVE
14.3% of CVEs· 100th percentile
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Soliton.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Soliton — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Soliton's Products

View all 1 CNAs →

Top CWEs