Wut manufactures a line of serial-to-network COM server appliances, including fixed and modular variants with varying port densities and specialized firmware builds, that bridge legacy serial devices to IP networks. The recurring vulnerability surface centers on authentication and input-handling gaps—including authentication bypass via spoofing, cross-site scripting in web interfaces, missing authentication for critical functions, unquoted search paths, and insufficient randomness in token generation—reflecting the challenges of retrofitting security into embedded serial-bridging appliances. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Wut over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-42785CRITICAL Multiple W&T products of the ComServer Series are prone to an authentication bypass. An unathenticated remote attacker, can log in without knowledge of the password by crafting a m | Nov 15, 2022 | 9.8 | 31 | NO | NO |
CVE-2022-42787HIGH Multiple W&T products of the Comserver Series use a small number space for allocating sessions ids. After login of an user an unathenticated remote attacker can brute force the use | Nov 10, 2022 | 8.8 | 28 | NO | NO |
CVE-2022-4098HIGH Multiple Wiesemann&Theis products of the ComServer Series are prone to an authentication bypass through IP spoofing. After a user logged in to the WBM of the Com-Server an unauthen | Dec 13, 2022 | 8.0 | 26 | NO | NO |
CVE-2024-25552HIGH A local attacker can gain administrative privileges by inserting an executable file in the path of the affected product. | Mar 1, 2024 | 7.8 | 22 | NO | NO |
CVE-2022-42786MEDIUM Multiple W&T Products of the ComServer Series are prone to an XSS attack. An authenticated remote Attacker can execute arbitrary web scripts or HTML via a crafted payload injected | Nov 10, 2022 | 5.4 | 21 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Wut.
Media articles that mention a CVE ID that affects a product developed by Wut — matched by CVE ID, not by vendor name.