Xantech manufactures audio/video control and distribution systems, with the observed vulnerability footprint concentrating in its WIC1200 wireless control product and associated firmware. The durable signal reflects web-interface and credential-handling weaknesses, recurrently including cross-site request forgery, cross-site scripting, and weak password encoding, typical of embedded control systems with browser-accessible management interfaces. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Xantech over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-0555HIGH A Cross-Site Request Forgery (CSRF) vulnerability has been found on WIC1200, affecting version 1.1. An authenticated user could lead another user into executing unwanted actions in | Jan 16, 2024 | 8.0 | 23 | NO | NO |
CVE-2024-0556MEDIUM A Weak Cryptography for Passwords vulnerability has been detected on WIC200 affecting version 1.1. This vulnerability allows a remote user to intercept the traffic and retrieve the | Jan 16, 2024 | 6.5 | 19 | NO | NO |
CVE-2024-0554MEDIUM A Cross-site scripting (XSS) vulnerability has been found on WIC1200, affecting version 1.1. An authenticated user could store a malicious javascript payload in the device model pa | Jan 16, 2024 | 5.4 | 18 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Xantech.
Media articles that mention a CVE ID that affects a product developed by Xantech — matched by CVE ID, not by vendor name.