Tandd manufactures industrial temperature and humidity data loggers and monitoring devices, including the TR-71W and TR-72W product lines, where vulnerability exposure centers on embedded web interfaces and management firmware. The recurring weakness classes—cross-site request forgery, improper authentication, path traversal, cross-site scripting, and incorrect authorization—reflect characteristic gaps in web-application hardening typical of IoT and industrial monitoring appliances. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Tandd over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-27388CRITICAL Improper authentication vulnerability in T&D Corporation and ESPEC MIC CORP. data logger products allows a remote unauthenticated attacker to login to the product as a registered u | May 23, 2023 | 9.8 | 28 | NO | NO |
CVE-2023-27387HIGH Cross-site request forgery (CSRF) in T&D Corporation and ESPEC MIC CORP. data logger products allows a remote unauthenticated attacker to conduct an arbitrary operation by having a | May 23, 2023 | 8.8 | 25 | NO | NO |
CVE-2022-29509HIGH Directory traversal vulnerability in T&D Data Server (Japanese Edition) Ver.2.22 and earlier, T&D Data Server (English Edition) Ver.2.30 and earlier, THERMO RECORDER DATA SERVER (J | Jun 14, 2022 | 7.5 | 25 | NO | NO |
CVE-2023-23545MEDIUM Missing authentication for critical function exists in T&D Corporation and ESPEC MIC CORP. data logger products, which may allow a remote unauthenticated attacker to alter the prod | May 23, 2023 | 5.3 | 19 | NO | NO |
CVE-2023-22654MEDIUM Client-side enforcement of server-side security issue exists in T&D Corporation and ESPEC MIC CORP. data logger products, which may lead to an arbitrary script execution on a logge | May 23, 2023 | 5.4 | 19 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Tandd.
Media articles that mention a CVE ID that affects a product developed by Tandd — matched by CVE ID, not by vendor name.