Twsz manufactures consumer Wi-Fi repeater and range-extension appliances, including the BE126 model line, which present a narrow but security-sensitive embedded device footprint. The observed vulnerability surface centers on authentication and command-handling weaknesses—hard-coded credentials, sensitive information exposure, improper authentication mechanisms, and OS command injection—that are characteristic of consumer networking firmware. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Twsz over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2017-13713HIGH T&W WIFI Repeater BE126 allows remote authenticated users to execute arbitrary code via shell metacharacters in the user parameter to cgi-bin/webupg. | Sep 7, 2017 | 8.8 | 41 | NO | YES |
CVE-2017-8770HIGH There is LFD (local file disclosure) on BE126 WIFI repeater 1.0 devices that allows attackers to read the entire filesystem on the device via a crafted getpage parameter. | Sep 20, 2017 | 7.5 | 39 | NO | YES |
CVE-2017-8772CRITICAL On BE126 WIFI repeater 1.0 devices, an attacker can log into telnet (which is open by default) with default credentials as root (username:"root" password:"root") and can: 1. Read t | Sep 20, 2017 | 9.8 | 31 | NO | NO |
CVE-2017-8771CRITICAL On BE126 WIFI repeater 1.0 devices, an attacker can log into telnet (which is open by default) with default credentials as root (username:"root" password:"root"). The attacker can | Sep 20, 2017 | 9.8 | 31 | NO | NO |
CVE-2018-9232HIGH Due to the lack of firmware authentication in the upgrade process of T&W WIFI Repeater BE126 devices, an attacker can craft a malicious firmware and use it as an update. | May 1, 2018 | 7.8 | 23 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Twsz.
Media articles that mention a CVE ID that affects a product developed by Twsz — matched by CVE ID, not by vendor name.