Vembu develops backup, disaster recovery, and storage virtualization appliances deployed in small-to-medium enterprise environments, with its vulnerability footprint concentrated in products such as BDR Suite, Offsite DR, and StoreGrid. Vulnerabilities affecting the vendor skew strongly toward critical severity and frequently acquire public exploit code, driven by recurring web-application and command-execution weaknesses including cross-site request forgery, cross-site scripting, OS command injection, and information exposure that are typical of management interfaces in backup infrastructure. Defenders should prioritize patching for these appliances, particularly internet-reachable instances; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Vembu over time
Signals from CVEs in this vendor scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-26471CRITICAL In VembuBDR before 4.2.0.1 and VembuOffsiteDR before 4.2.0.1, the http API located at /sgwebservice_o.php accepts a command argument. Using this command argument an unauthenticated | Jun 8, 2021 | 9.8 | 31 | NO | NO |
CVE-2021-26473CRITICAL In VembuBDR before 4.2.0.1 and VembuOffsiteDR before 4.2.0.1 the http API located at /sgwebservice_o.php action logFilePath allows an attacker to write arbitrary files in the conte | Jun 8, 2021 | 9.8 | 30 | NO | NO |
CVE-2021-26472CRITICAL In VembuBDR before 4.2.0.1 and VembuOffsiteDR before 4.2.0.1 installed on Windows, the http API located at /consumerweb/secure/download.php. Using this command argument an unauthen | Jun 8, 2021 | 9.8 | 29 | NO | NO |
CVE-2021-26474HIGH Various Vembu products allow an attacker to execute a (non-blind) http-only Cross Site Request Forgery (Other products or versions of products in this family may be affected too.) | Jun 8, 2021 | 8.8 | 26 | NO | NO |
CVE-2014-10079MEDIUM In Vembu StoreGrid 4.4.x, the front page of the server web interface leaks the private IP address in the "ipaddress" hidden form value of the HTML source code, which is disclosed b | Feb 23, 2019 | 5.3 | 26 | NO | YES |
CVE-2014-10078MEDIUM Vembu StoreGrid 4.4.x has XSS in interface/registercustomer/onlineregsuccess.php, interface/registerreseller/onlineregfailure.php, interface/registerclient/onlineregfailure.php, an | Feb 23, 2019 | 6.1 | 26 | NO | YES |
CVE-2021-43458HIGH An Unquoted Service Path vulnerability exits in Vembu BDR 4.2.0.1 via a specially crafted file in the (1) hsflowd, (2) VembuBDR360Agent, or (3) VembuOffice365Agent service paths. | Apr 4, 2022 | 7.8 | 25 | NO | NO |
Signals from CVEs in this vendor scope (7 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Vembu.
Media articles that mention a CVE ID that affects a product developed by Vembu — matched by CVE ID, not by vendor name.