Vyos develops a network operating system for routing and firewall appliances, and its modest vulnerability footprint centers on OS command injection weaknesses that reflect the command-processing exposure inherent to a systems-level networking platform. Treat this as a compact vendor profile rather than a broad trend line; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Vyos over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-18556CRITICAL A privilege escalation issue was discovered in VyOS 1.1.8. The default configuration also allows operator users to execute the pppd binary with elevated (sudo) permissions. Certain | Dec 17, 2018 | 9.9 | 49 | NO | YES |
CVE-2018-18555CRITICAL A sandbox escape issue was discovered in VyOS 1.1.8. It provides a restricted management shell for operator users to administer the device. By issuing various shell special charact | Dec 17, 2018 | 9.9 | 29 | NO | NO |
CVE-2025-30095CRITICAL VyOS 1.3 through 1.5 (fixed in 1.4.2) or any Debian-based system using dropbear in combination with live-build has the same Dropbear private host keys across different installation | Mar 31, 2025 | 9.0 | 27 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Vyos.
Media articles that mention a CVE ID that affects a product developed by Vyos — matched by CVE ID, not by vendor name.