Thermofisher's vulnerability footprint centers on a narrow range of genomic sequencing and laboratory instrumentation platforms, including the Ion Torrent software suite and associated field devices, which are deployed in research and clinical settings where data integrity and access control are critical. Vulnerabilities affecting these products skew strongly toward critical-severity outcomes and frequently acquire public exploit code, recurring through weakness classes including sensitive information disclosure, authentication bypass through spoofing, improper input validation, path traversal, and insufficiently protected credentials that reflect the legacy authentication and data-handling patterns common to specialized laboratory software. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Thermofisher over time
Signals from CVEs in this vendor scope (8 CVEs).
8 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2017-11165CRITICAL dataTaker DT80 dEX 1.50.012 allows remote attackers to obtain sensitive credential and configuration information via a direct request for the /services/getFile.cmd?userfile=config. | Jul 12, 2017 | 9.8 | 83 | NO | YES |
CVE-2025-54303CRITICAL The Thermo Fisher Torrent Suite Django application 5.18.1 has weak default credentials, which are stored as fixtures for the Django ORM API. The ionadmin user account can be used t | Dec 4, 2025 | 9.8 | 31 | NO | NO |
CVE-2025-53963CRITICAL An issue was discovered on Thermo Fisher Ion Torrent OneTouch 2 INS1005527 devices. They run an SSH server accessible over the default port 22. The root account has a weak default | Dec 4, 2025 | 9.8 | 31 | NO | NO |
CVE-2025-54304CRITICAL An issue was discovered on Thermo Fisher Ion Torrent OneTouch 2 INS1005527 devices. When they are powered on, an X11 display server is started. The display server listens on all ne | Dec 4, 2025 | 9.8 | 30 | NO | NO |
CVE-2025-54307HIGH An issue was discovered in the Thermo Fisher Torrent Suite Django application 5.18.1. The /configure/plugins/plugin/upload/zip/ and /configure/newupdates/offline/bundle/upload/ end | Dec 4, 2025 | 8.8 | 28 | NO | NO |
CVE-2025-54305HIGH An issue was discovered in the Thermo Fisher Torrent Suite Django application 5.18.1. One of the middlewares included in this application, LocalhostAuthMiddleware, authenticates us | Dec 4, 2025 | 7.8 | 26 | NO | NO |
CVE-2025-54306HIGH An issue was discovered in the Thermo Fisher Torrent Suite Django application 5.18.1. A remote code execution vulnerability exists in the network configuration functionality, stemm | Dec 4, 2025 | 7.2 | 24 | NO | NO |
CVE-2017-11349CRITICAL dataTaker DT8x dEX 1.72.007 allows remote attackers to compose programs or schedules, for purposes such as sending e-mail messages or making outbound connections to FTP servers for | Jul 17, 2017 | 9.8 | 24 | NO | NO |
Signals from CVEs in this vendor scope (8 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Thermofisher.
Media articles that mention a CVE ID that affects a product developed by Thermofisher — matched by CVE ID, not by vendor name.