Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Wellintech

First CVE: Jan 11, 2011Active for: 16 yearsTotal CVEs: 20
59.8
VTI Score
TOP TARGET

Wellintech develops a focused suite of industrial control system (ICS) and supervisory control and data acquisition (SCADA) software, including products such as Kingview, KingSCADA, KingHistorian, KingAlarm&Event, and KingGraphic, which are deployed in critical infrastructure environments across manufacturing, utilities, and process automation. The vendor's vulnerability exposure concentrates in memory-safety and access-control weaknesses characteristic of native-code ICS platforms: buffer-boundary violations, path-traversal flaws, sensitive-information disclosure, improper authentication, and code-injection conditions recur across the product line. While the absolute volume is modest relative to broad enterprise software vendors, the prominence of these products in operational technology networks and the recurring code-execution and privilege-escalation potential of the observed weakness classes elevate the practical risk; public exploit code has frequently accompanied disclosures. Defenders operating Wellintech deployments should prioritize patching of authentication and memory-safety flaws and implement network segmentation to limit lateral movement from a compromised ICS node; current exploitation activity and severity counts are shown alongside this summary.

FAUCET AI Generated
20
Total CVEs
More Total CVEs than 96% of tracked vendors
0.7
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 10% of tracked vendors
8.2
Avg CVSS Score
Higher Avg CVSS Score than 80% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Wellintech over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jan 11, 2011
15 years ago
Most Recent CVE
Mar 20, 2023
1,222 days ago

Products(5 total)

Top CVEs

Signals from CVEs in this vendor scope (20 CVEs).

20 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2012-4711HIGH
Buffer overflow in kingMess.exe 65.20.2003.10300 in WellinTech KingView 6.52, kingMess.exe 65.20.2003.10400 in KingView 6.53, and kingMess.exe 65.50.2011.18049 in KingView 6.55 all
Feb 15, 201310.081NOYES
CVE-2013-2827HIGH
An unspecified ActiveX control in WellinTech KingSCADA before 3.1.2, KingAlarm&Event before 3.1, and KingGraphic before 3.1.2 allows remote attackers to download arbitrary DLL code
Jan 15, 20147.564NOYES
CVE-2011-3142HIGH
Stack-based buffer overflow in an ActiveX control in KVWebSvr.dll in WellinTech KingView 6.52 and 6.53 allows remote attackers to execute arbitrary code via a long second argument
Aug 16, 201110.060NOYES
CVE-2011-0406HIGH
Heap-based buffer overflow in HistorySvr.exe in WellinTech KingView 6.53 allows remote attackers to execute arbitrary code via a long request to TCP port 777.
Jan 11, 201110.052NOYES
CVE-2012-1831HIGH
Heap-based buffer overflow in WellinTech KingView 6.53 allows remote attackers to execute arbitrary code via a crafted packet to TCP port 555.
Jul 5, 201210.048NOYES
CVE-2014-0787HIGH
Stack-based buffer overflow in WellinTech KingSCADA before 3.1.2.13 allows remote attackers to execute arbitrary code via a crafted packet.
Apr 12, 201410.043NOYES
CVE-2012-1830HIGH
Stack-based buffer overflow in WellinTech KingView 6.53 allows remote attackers to execute arbitrary code via a crafted packet to TCP port 555.
Jul 5, 201210.043NOYES
CVE-2022-43663CRITICAL
An integer conversion vulnerability exists in the SORBAx64.dll RecvPacket functionality of WellinTech KingHistorian 35.01.00.05. A specially crafted network packet can lead to a bu
Mar 20, 20239.837NONO
CVE-2013-6127MEDIUM
The SUPERGRIDLib.SuperGrid ActiveX control in SuperGrid.ocx before 65.30.30000.10002 in WellinTech KingView before 6.53 does not properly restrict ReplaceDBFile method calls, which
Oct 25, 20135.835NOYES
CVE-2011-4536HIGH
Heap-based buffer overflow in nettransdll.dll in HistorySvr.exe (aka HistoryServer.exe) in WellinTech KingView 6.53 and 65.30.2010.18018 allows remote attackers to execute arbitrar
Dec 27, 201110.033NONO
View all 20 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products20 CVEs
20%
70%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local0 (0.0%)
Network3 (15.0%)
Unknown17 (85.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low3 (15.0%)
High0 (0.0%)
Unknown17 (85.0%)
User Interaction
None3 (15.0%)
Unknown17 (85.0%)
Required0 (0.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None3 (15.0%)
Unknown17 (85.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (20 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
2 CVEs
10.0% of CVEs· 98th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
9 CVEs
45.0% of CVEs· 81st percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Wellintech.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Wellintech — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Wellintech's Products

View all 4 CNAs →

Top CWEs