Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Weidmueller

First CVE: Dec 6, 2019Active for: 7 yearsTotal CVEs: 20
36.9
VTI Score
Medium

Weidmueller manufactures industrial automation and networking devices, particularly wireless access points and connectivity appliances deployed in manufacturing and process-control environments where uptime and physical security are critical. The vendor's vulnerability profile, while modestly represented in overall volume, ranks among the more prominent in the industrial networking space and skews toward critical-severity outcomes across its product line. Exposure concentrates in its wireless access-point and industrial Ethernet products—including its IE-WL series across regional variants—and recurs through OS command injection, hard-coded and insufficiently protected credentials, and classic buffer overflows that reflect the embedded firmware and legacy authentication postures common in operational technology. These weakness classes are particularly consequential in industrial settings, where remote code execution through command injection or credential compromise can disrupt production and compromise physical systems. Defenders managing industrial sites should prioritize inventory and segmentation of these devices and monitor for firmware updates closely; live severity and exploitation counts are shown alongside this summary.

FAUCET AI Generated
20
Total CVEs
More Total CVEs than 96% of tracked vendors
0.1
Avg CVEs / Product / Year
Bottom 1%
8.3
Avg CVSS Score
Higher Avg CVSS Score than 81% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Weidmueller over time

Volume of CVEsAvg CVSS Base Score
First CVE
Dec 6, 2019
6 years ago
Most Recent CVE
Dec 14, 2022
1,318 days ago

Products(115 total)

Top CVEs

Signals from CVEs in this vendor scope (20 CVEs).

20 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2019-16672CRITICAL
An issue was discovered on Weidmueller IE-SW-VL05M 3.6.6 Build 16102415, IE-SW-VL08MT 3.5.2 Build 16102415, and IE-SW-PL10M 3.3.16 Build 16102416 devices. Sensitive Credentials dat
Dec 6, 20199.830NONO
CVE-2021-20999CRITICAL
In Weidmüller u-controls and IoT-Gateways in versions up to 1.12.1 a network port intended only for device-internal usage is accidentally accessible via external network interfaces
May 13, 20219.828NONO
CVE-2019-16670CRITICAL
An issue was discovered on Weidmueller IE-SW-VL05M 3.6.6 Build 16102415, IE-SW-VL08MT 3.5.2 Build 16102415, and IE-SW-PL10M 3.3.16 Build 16102416 devices. The Authentication mechan
Dec 6, 20199.827NONO
CVE-2021-33538HIGH
In Weidmueller Industrial WLAN devices in multiple versions an exploitable improper access control vulnerability exists in the iw_webs account settings functionality. A specially c
Jun 25, 20218.826NONO
CVE-2021-33535HIGH
In Weidmueller Industrial WLAN devices in multiple versions an exploitable format string vulnerability exists in the iw_console conio_writestr functionality. A specially crafted ti
Jun 25, 20218.826NONO
CVE-2021-33533HIGH
In Weidmueller Industrial WLAN devices in multiple versions an exploitable command injection vulnerability exists in the iw_webs functionality. A specially crafted iw_serverip para
Jun 25, 20218.826NONO
CVE-2021-33532HIGH
In Weidmueller Industrial WLAN devices in multiple versions an exploitable command injection vulnerability exists in the iw_webs functionality. A specially crafted diagnostic scrip
Jun 25, 20218.826NONO
CVE-2021-33530HIGH
In Weidmueller Industrial WLAN devices in multiple versions an exploitable command injection vulnerability exists in encrypted diagnostic script functionality of the devices. A spe
Jun 25, 20218.826NONO
CVE-2021-33528HIGH
In Weidmueller Industrial WLAN devices in multiple versions an exploitable privilege escalation vulnerability exists in the iw_console functionality. A specially crafted menu selec
Jun 25, 20218.826NONO
CVE-2021-33537HIGH
In Weidmueller Industrial WLAN devices in multiple versions an exploitable remote code execution vulnerability exists in the iw_webs configuration parsing functionality. A speciall
Jun 25, 20218.825NONO
View all 20 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products20 CVEs
15%
65%
20%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local1 (5.0%)
Network19 (95.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low20 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None18 (90.0%)
Unknown0 (0.0%)
Required2 (10.0%)
Privileges Required
Low10 (50.0%)
High2 (10.0%)
None8 (40.0%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (20 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Weidmueller.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Weidmueller — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Weidmueller's Products

View all 2 CNAs →

Top CWEs