Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Thermofisher

First CVE: Jul 12, 2017Active for: 9 yearsTotal CVEs: 8

Thermofisher's vulnerability footprint centers on a narrow range of genomic sequencing and laboratory instrumentation platforms, including the Ion Torrent software suite and associated field devices, which are deployed in research and clinical settings where data integrity and access control are critical. Vulnerabilities affecting these products skew strongly toward critical-severity outcomes and frequently acquire public exploit code, recurring through weakness classes including sensitive information disclosure, authentication bypass through spoofing, improper input validation, path traversal, and insufficiently protected credentials that reflect the legacy authentication and data-handling patterns common to specialized laboratory software. Current severity, exploitation, and exposure counts are shown alongside this summary.

FAUCET AI Generated
8
Total CVEs
More Total CVEs than 90% of tracked vendors
0.6
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 9% of tracked vendors
9.1
Avg CVSS Score
Higher Avg CVSS Score than 88% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Thermofisher over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jul 12, 2017
9 years ago
Most Recent CVE
Dec 4, 2025
235 days ago

Products(7 total)

Top CVEs

Signals from CVEs in this vendor scope (8 CVEs).

8 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2017-11165CRITICAL
dataTaker DT80 dEX 1.50.012 allows remote attackers to obtain sensitive credential and configuration information via a direct request for the /services/getFile.cmd?userfile=config.
Jul 12, 20179.883NOYES
CVE-2025-54303CRITICAL
The Thermo Fisher Torrent Suite Django application 5.18.1 has weak default credentials, which are stored as fixtures for the Django ORM API. The ionadmin user account can be used t
Dec 4, 20259.831NONO
CVE-2025-53963CRITICAL
An issue was discovered on Thermo Fisher Ion Torrent OneTouch 2 INS1005527 devices. They run an SSH server accessible over the default port 22. The root account has a weak default
Dec 4, 20259.831NONO
CVE-2025-54304CRITICAL
An issue was discovered on Thermo Fisher Ion Torrent OneTouch 2 INS1005527 devices. When they are powered on, an X11 display server is started. The display server listens on all ne
Dec 4, 20259.830NONO
CVE-2025-54307HIGH
An issue was discovered in the Thermo Fisher Torrent Suite Django application 5.18.1. The /configure/plugins/plugin/upload/zip/ and /configure/newupdates/offline/bundle/upload/ end
Dec 4, 20258.828NONO
CVE-2025-54305HIGH
An issue was discovered in the Thermo Fisher Torrent Suite Django application 5.18.1. One of the middlewares included in this application, LocalhostAuthMiddleware, authenticates us
Dec 4, 20257.826NONO
CVE-2025-54306HIGH
An issue was discovered in the Thermo Fisher Torrent Suite Django application 5.18.1. A remote code execution vulnerability exists in the network configuration functionality, stemm
Dec 4, 20257.224NONO
CVE-2017-11349CRITICAL
dataTaker DT8x dEX 1.72.007 allows remote attackers to compose programs or schedules, for purposes such as sending e-mail messages or making outbound connections to FTP servers for
Jul 17, 20179.824NONO
View all 8 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products8 CVEs
38%
63%
Severity distribution among all CVEs352,785 CVEs
45%
40%
11%
HighCritical
Attack Vector
Local1 (12.5%)
Network7 (87.5%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low8 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None8 (100.0%)
Unknown0 (0.0%)
Required0 (0.0%)
Privileges Required
Low2 (25.0%)
High1 (12.5%)
None5 (62.5%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (8 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
1 CVE
12.5% of CVEs· 97th percentile
ExploitDB
1 CVE
12.5% of CVEs· 76th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Thermofisher.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Thermofisher — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Thermofisher's Products

View all 1 CNAs →

Top CWEs