Washington develops a focused set of products spanning basestation infrastructure, transit-management systems such as I-Tech TrainSmart, and Pine, with vulnerabilities clustering around data-handling weaknesses including deserialization of untrusted data, improper input validation, SQL injection, and array-index validation failures. These weakness classes reflect the parsing and database-interaction demands typical of networked infrastructure and transit-control software; current severity, exploitation, and exposure details are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Washington over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-36520HIGH A SQL injection vulnerability in I-Tech Trainsmart r1044 exists via a evaluation/assign-evaluation?id= URI. | Apr 16, 2023 | 7.5 | 36 | NO | YES |
CVE-2025-4905CRITICAL A vulnerability was found in iop-apl-uw basestation3 up to 3.0.4 and classified as problematic. This issue affects the function load_qc_pickl of the file basestation3/QC.py. The ma | May 19, 2025 | 9.8 | 26 | NO | NO |
CVE-2003-0721HIGH Integer signedness error in rfc2231_get_param from strings.c in PINE before 4.58 allows remote attackers to execute arbitrary code via an email that causes an out-of-bounds array a | Sep 17, 2003 | 7.5 | 20 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Washington.
Media articles that mention a CVE ID that affects a product developed by Washington — matched by CVE ID, not by vendor name.