Waveshare specializes in embedded networking and serial-conversion hardware, with its vulnerability footprint concentrated in industrial and IoT connectivity products such as RS232/485-to-WiFi and Ethernet bridges. The recurring exposure reflects the product's network-facing role and firmware update attack surface, centered on weakness classes including cleartext transmission of sensitive data, improper access control, insufficiently protected credentials, and channel accessibility by non-endpoints that are characteristic of devices designed for direct industrial deployment. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Waveshare over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-63362CRITICAL Waveshare RS232/485 TO WIFI ETH (B) Serial to Ethernet/Wi-Fi Gateway Firmware V3.1.1.0: HW 4.3.2.1: Webpage V7.04T.07.002880.0301 allows attackers to set the Administrator password | Dec 4, 2025 | 9.8 | 34 | NO | NO |
CVE-2025-63363HIGH A lack of Management Frame Protection in Waveshare RS232/485 TO WIFI ETH (B) Serial to Ethernet/Wi-Fi Gateway Firmware V3.1.1.0: HW 4.3.2.1: Webpage V7.04T.07.002880.0301 allows at | Dec 4, 2025 | 7.5 | 24 | NO | NO |
CVE-2025-63364HIGH Waveshare RS232/485 TO WIFI ETH (B) Serial to Ethernet/Wi-Fi Gateway Firmware V3.1.1.0: HW 4.3.2.1: Webpage V7.04T.07.002880.0301 was discovered to transmit Administrator credentia | Dec 4, 2025 | 7.5 | 24 | NO | NO |
CVE-2025-63361MEDIUM Waveshare RS232/485 TO WIFI ETH (B) Serial to Ethernet/Wi-Fi Gateway Firmware V3.1.1.0: HW 4.3.2.1: Webpage V7.04T.07.002880.0301 was discovered to render the Administrator passwor | Dec 4, 2025 | 5.7 | 20 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Waveshare.
Media articles that mention a CVE ID that affects a product developed by Waveshare — matched by CVE ID, not by vendor name.