Xinje manufactures programmable logic controllers and related industrial automation tools, with its vulnerability footprint concentrating on the XD/E-series PLC and its associated programming platform. The observed weakness classes—uncontrolled search path elements, improper resource shutdown, and relative path traversal—reflect input-handling and resource-management issues typical of engineering tools and firmware operating in less-regulated development contexts; current severity and exploitation activity are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Xinje over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-34605HIGH A zip slip vulnerability in XINJE XD/E Series PLC Program Tool up to version v3.5.1 can provide an attacker with arbitrary file write privilege when opening a specially-crafted pro | May 11, 2022 | 7.3 | 24 | NO | NO |
CVE-2021-34606HIGH A vulnerability exists in XINJE XD/E Series PLC Program Tool in versions up to v3.5.1 that can allow an authenticated, local attacker to load a malicious DLL. Local access is requi | May 11, 2022 | 7.3 | 23 | NO | NO |
CVE-2023-5463HIGH A vulnerability was found in XINJE XDPPro up to 3.7.17a. It has been rated as critical. Affected by this issue is some unknown functionality in the library cfgmgr32.dll. The manipu | Oct 9, 2023 | 7.8 | 22 | NO | NO |
CVE-2023-5462HIGH A vulnerability was found in XINJE XD5E-30R-E 3.5.3b. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the component Modbus Handler. | Oct 9, 2023 | 7.5 | 22 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Xinje.
Media articles that mention a CVE ID that affects a product developed by Xinje — matched by CVE ID, not by vendor name.