Vonets manufactures small wireless access-point products such as the VAP11G series, which serve as bridge and repeater devices in enterprise and consumer networking environments. These devices exhibit a durable pattern of vulnerabilities centered on OS command injection, path traversal, forced browsing, and access-control weaknesses—attack surfaces characteristic of embedded firmware with limited input validation and authentication mechanisms. The vendor's disclosures skew strongly toward critical-severity outcomes, reflecting the internet-facing nature of these devices and the potential for unauthenticated network compromise. Current exploitation activity, severity distribution, and exposure scope are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Vonets over time
Signals from CVEs in this vendor scope (11 CVEs).
11 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-37023CRITICAL Multiple OS command injection vulnerabilities affecting Vonets
industrial wifi bridge relays and wifi bridge repeaters, software
versions 3.3.23.6.9 and prior, enable an authen | Aug 12, 2024 | 9.9 | 30 | NO | NO |
CVE-2024-39791CRITICAL Stack-based buffer overflow vulnerabilities affecting Vonets
industrial wifi bridge relays and wifi bridge repeaters, software versions
3.3.23.6.9 and prior, enable an unau | Aug 12, 2024 | 9.8 | 29 | NO | NO |
CVE-2024-42001CRITICAL An improper authentication vulnerability affecting Vonets
industrial wifi bridge relays and wifi bridge repeaters, software versions
3.3.23.6.9 and prior enables an unaut | Aug 12, 2024 | 9.8 | 28 | NO | NO |
CVE-2024-41161CRITICAL Use of hard-coded credentials vulnerability affecting Vonets industrial wifi bridge relays and wifi bridge repeaters, software versions
3.3.23.6.9 and prior, enables an unauthenti | Aug 8, 2024 | 9.8 | 28 | NO | NO |
CVE-2024-29082HIGH Improper access control vulnerability affecting Vonets
industrial wifi bridge relays and wifi bridge repeaters, software versions 3.3.23.6.9
and prior, enables an unauthenticate | Aug 12, 2024 | 8.6 | 26 | NO | NO |
CVE-2024-39815HIGH Improper check or handling of exceptional conditions vulnerability
affecting Vonets
industrial wifi bridge relays and wifi bridge repeaters, software versions 3.3.23.6.9 and | Aug 12, 2024 | 7.5 | 25 | NO | NO |
CVE-2024-41936HIGH A directory traversal vulnerability affecting Vonets industrial wifi bridge relays and wifi bridge repeaters, software versions 3.3.23.6.9
and prior, enables an unauthenticated re | Aug 12, 2024 | 7.5 | 24 | NO | NO |
CVE-2024-46329HIGH VONETS VAP11G-300 v3.3.23.6.9 was discovered to contain a command injection vulnerability via the SystemCommand object. | Sep 26, 2024 | 8.0 | 23 | NO | NO |
CVE-2024-46328HIGH VONETS VAP11G-300 v3.3.23.6.9 was discovered to contain hardcoded credentials for several different privileged accounts, including root. | Sep 26, 2024 | 8.0 | 23 | NO | NO |
CVE-2024-46330HIGH VONETS VAP11G-300 v3.3.23.6.9 was discovered to contain a command injection vulnerability via the iptablesWebsFilterRun object. | Sep 26, 2024 | 7.4 | 22 | NO | NO |
Signals from CVEs in this vendor scope (11 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Vonets.
Media articles that mention a CVE ID that affects a product developed by Vonets — matched by CVE ID, not by vendor name.