Systrome produces a focused line of industrial-grade security appliances and firewalls, primarily the Cumilon ISG series, which are deployed in network infrastructure and edge-security contexts. Vulnerabilities affecting these products center on web-interface input handling and administrative functionality, with recurring weaknesses in cross-site request forgery, path traversal, cross-site scripting, and OS command injection that are typical of embedded web management consoles. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Systrome over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-7383HIGH An issue was discovered on Systrome Cumilon ISG-600C, ISG-600H, and ISG-800W devices with firmware V1.1-R2.1_TRUNK-20181105.bin. A shell command injection occurs by editing the des | Mar 21, 2019 | 7.8 | 25 | NO | NO |
CVE-2019-7387MEDIUM A local file inclusion vulnerability exists in the web interface of Systrome Cumilon ISG-600C, ISG-600H, and ISG-800W 1.1-R2.1_TRUNK-20180914.bin devices. When the export function | Feb 4, 2019 | 6.5 | 22 | NO | NO |
CVE-2018-19525MEDIUM An issue was discovered on Systrome ISG-600C, ISG-600H, and ISG-800W 1.1-R2.1_TRUNK-20180914.bin devices. There is CSRF via /ui/?g=obj_keywords_add and /ui/?g=obj_keywords_addsave | Mar 21, 2019 | 6.1 | 21 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Systrome.
Media articles that mention a CVE ID that affects a product developed by Systrome — matched by CVE ID, not by vendor name.