Wyrestorm's vulnerability footprint centers on its Apollo VX20 professional display and control systems, with observed weaknesses centered on information disclosure and access control—including cleartext transmission of sensitive data, exposure of credentials or configuration to unauthorized actors, and improper access control mechanisms. This reflects the operational-technology context typical of networked AV and control infrastructure, where legacy implementations often prioritize availability and integration over cryptographic protection. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Wyrestorm over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-25735CRITICAL An issue was discovered on WyreStorm Apollo VX20 devices before 1.3.58. Remote attackers can discover cleartext passwords via a SoftAP /device/config GET request. | Mar 27, 2024 | 9.1 | 73 | NO | YES |
CVE-2024-25736HIGH An issue was discovered on WyreStorm Apollo VX20 devices before 1.3.58. Remote attackers can restart the device via a /device/reboot GET request. | Mar 27, 2024 | 7.5 | 33 | NO | YES |
CVE-2024-25734HIGH An issue was discovered on WyreStorm Apollo VX20 devices before 1.3.58. The TELNET service prompts for a password only after a valid username is entered, which might make it easier | Mar 27, 2024 | 7.5 | 29 | NO | YES |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Wyrestorm.
Media articles that mention a CVE ID that affects a product developed by Wyrestorm — matched by CVE ID, not by vendor name.