Vatilon's vulnerability footprint centers on its PA4 appliance and related firmware, where the durable signal reflects the product's network-facing role and the recurring transmission and access-control weaknesses characteristic of embedded systems handling sensitive data. The observed pattern includes cleartext transmission of sensitive information and path-traversal vulnerabilities that typically arise in appliance configuration and logging interfaces. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Vatilon over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-67160HIGH An issue in Vatilon v1.12.37-20240124 allows attackers to access sensitive directories and files via a directory traversal. | Jan 2, 2026 | 7.5 | 26 | NO | NO |
CVE-2025-67159HIGH Vatilon v1.12.37-20240124 was discovered to transmit user credentials in plaintext. | Jan 2, 2026 | 7.5 | 26 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Vatilon.
Media articles that mention a CVE ID that affects a product developed by Vatilon — matched by CVE ID, not by vendor name.