Telosalliance develops audio and broadcast networking products including the Omnia MPX Node and Z/IP One lines, which serve professional media infrastructure. The vendor's vulnerability profile centers on authentication and access-control weaknesses—including authorization bypasses, path traversal, OS command injection, incorrect default permissions, and missing authorization checks—typical of networked appliances where configuration and command-injection boundaries require careful management. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Telosalliance over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-36642CRITICAL A local file disclosure vulnerability in /appConfig/userDB.json of Telos Alliance Omnia MPX Node through 1.0.0-1.4.9 allows attackers to access users credentials which makes him ab | Sep 2, 2022 | 9.8 | 47 | NO | YES |
CVE-2022-43325CRITICAL An unauthenticated command injection vulnerability in the product license validation function of Telos Alliance Omnia MPX Node 1.3.* - 1.4.* allows attackers to execute arbitrary c | Dec 2, 2022 | 9.8 | 31 | NO | NO |
CVE-2022-45562HIGH Insecure permissions in Telos Alliance Omnia MPX Node v1.0.0 to v1.4.9 allow attackers to manipulate and access system settings with backdoor account low privilege, this can lead t | Dec 2, 2022 | 8.8 | 28 | NO | NO |
CVE-2022-43326HIGH An Insecure Direct Object Reference (IDOR) vulnerability in the password reset function of Telos Alliance Omnia MPX Node 1.0.0-1.4.[*] allows attackers to arbitrarily change user a | Nov 29, 2022 | 7.5 | 25 | NO | NO |
CVE-2020-17383CRITICAL A directory traversal vulnerability on Telos Z/IP One devices through 4.0.0r grants an unauthenticated individual root level access to the device's file system. This can be used to | Jan 24, 2022 | 9.8 | 25 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Telosalliance.
Media articles that mention a CVE ID that affects a product developed by Telosalliance — matched by CVE ID, not by vendor name.