Webhmi maintains a focused industrial control or embedded-systems product line centered on web-accessible HMI (human-machine interface) firmware, presenting an attack surface concentrated in web-facing input handling and system-command execution contexts. The durable signal across its disclosures centers on authentication bypass, cross-site scripting, OS command injection, and unrestricted file upload weaknesses—a pattern typical of web interfaces layered over privileged system access, where input validation and authentication boundaries are critical defenses.
The number and severity of CVEs published that impact products developed by Webhmi over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-43936CRITICAL The software allows the attacker to upload or transfer files of dangerous types to the WebHMI portal, that may be automatically processed within the product's environment or lead t | Dec 6, 2021 | 9.8 | 62 | NO | YES |
CVE-2021-43931CRITICAL The authentication algorithm of the WebHMI portal is sound, but the implemented mechanism can be bypassed as the result of a separate weakness that is primary to the authentication | Dec 6, 2021 | 9.8 | 30 | NO | NO |
CVE-2022-2253CRITICAL A user with administrative privileges in Distributed Data Systems WebHMI 4.1.1.7662 may send OS commands to execute on the host server. | Jul 1, 2022 | 9.1 | 29 | NO | NO |
CVE-2022-2254MEDIUM A user with administrative privileges in Distributed Data Systems WebHMI 4.1.1.7662 can store a script that could impact other logged in users. | Jul 1, 2022 | 4.8 | 19 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Webhmi.
Media articles that mention a CVE ID that affects a product developed by Webhmi — matched by CVE ID, not by vendor name.