Xspeeder is a niche vendor whose vulnerability exposure centers on its SXZOS product, with the durable signal dominated by application-layer code-injection and eval-injection weaknesses. These weakness classes reflect improper handling of dynamically evaluated code and code generation, representing a structural input-validation risk in the product's execution model; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Xspeeder over time
Signals from CVEs in this vendor scope (1 CVEs).
1 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-54322CRITICAL Xspeeder SXZOS through 2025-12-26 allows root remote code execution via base64-encoded Python code in the chkid parameter to vLogin.py. The title and oIP parameters are also used. | Dec 27, 2025 | 9.8 | 44 | NO | NO |
Signals from CVEs in this vendor scope (1 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Xspeeder.
Media articles that mention a CVE ID that affects a product developed by Xspeeder — matched by CVE ID, not by vendor name.