Uchida develops a modest portfolio of presentation and asset-management products, notably the Wivia wireless presentation system and AssetBase, which surface client-side and web-application input-handling vulnerabilities. The recurring weakness classes—cross-site scripting, OS command injection, and client-side security enforcement gaps—reflect typical risks in browser-facing and shell-accessible interfaces; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Uchida over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-41385HIGH An OS Command Injection issue exists in wivia 5 all versions. If this vulnerability is exploited, an arbitrary OS command may be executed by a logged-in administrative user. | May 30, 2025 | 7.2 | 21 | NO | NO |
CVE-2025-47697HIGH Client-side enforcement of server-side security issue exists in wivia 5 all versions. If exploited, an unauthenticated attacker may bypass authentication and operate the affected d | May 30, 2025 | 7.5 | 20 | NO | NO |
CVE-2025-41406MEDIUM Cross-site scripting vulnerability exists in wivia 5 all versions. If exploited, when a user connects to the affected device with a specific operation, an arbitrary script may be e | May 30, 2025 | 6.1 | 18 | NO | NO |
CVE-2017-2134MEDIUM Cross-site scripting vulnerability in ASSETBASE 8.0 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | Apr 28, 2017 | 6.1 | 18 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Uchida.
Media articles that mention a CVE ID that affects a product developed by Uchida — matched by CVE ID, not by vendor name.