Wayos develops a focused line of networking and industrial appliances, primarily represented by the FBM-291W and IBR-7150 product families, that serve as gateways and access points in specialized deployments. Observed vulnerabilities in these products cluster around command injection, buffer overflow, and web-layer flaws including cross-site scripting and cross-site request forgery, reflecting the intersection of embedded device firmware and web-based management interfaces. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Wayos over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-37794CRITICAL WAYOS FBM-291W 19.09.11V was discovered to contain a command injection vulnerability via the component /upgrade_filter.asp. | Jul 14, 2023 | 9.8 | 30 | NO | NO |
CVE-2023-37793CRITICAL WAYOS FBM-291W 19.09.11V was discovered to contain a buffer overflow via the component /upgrade_filter.asp. | Jul 14, 2023 | 9.8 | 26 | NO | NO |
CVE-2022-41489HIGH WAYOS LQ_09 22.03.17V was discovered to contain a Cross-Site Request Forgery (CSRF) which allows attackers to send crafted requests to the server from the affected device. This vul | Oct 13, 2022 | 8.1 | 26 | NO | NO |
CVE-2024-44383MEDIUM WAYOS FBM-291W v19.09.11 is vulnerable to Command Execution via msp_info_htm. | Sep 4, 2024 | 6.8 | 20 | NO | NO |
CVE-2024-22547MEDIUM WayOS IBR-7150 <17.06.23 is vulnerable to Cross Site Scripting (XSS). | Feb 22, 2024 | 4.7 | 15 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Wayos.
Media articles that mention a CVE ID that affects a product developed by Wayos — matched by CVE ID, not by vendor name.