Zumtobel's vulnerability profile centers on its NetLink CCD lighting control and networked device-management products, with the observed exposure rooted in embedded firmware components. The recurring weakness classes—buffer overflows, OS command injection, and hard-coded credentials—are characteristic of legacy networked embedded systems where input validation and credential management practices lag behind modern standards. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Zumtobel over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-23325CRITICAL Zumtobel Netlink CCD Onboard 3.74 - Firmware 3.80 was discovered to contain a command injection vulnerability via the NetHostname parameter. | Nov 29, 2023 | 9.8 | 30 | NO | NO |
CVE-2023-23324CRITICAL Zumtobel Netlink CCD Onboard 3.74 - Firmware 3.80 was discovered to contain hardcoded credentials for the Administrator account. | Nov 29, 2023 | 9.8 | 29 | NO | NO |
CVE-2023-24294HIGH Zumtobel Netlink CCD Onboard v3.74 - Firmware v3.80 was discovered to contain a buffer overflow via the component NetlinkWeb::Information::SetDeviceIdentification. | Nov 29, 2023 | 7.5 | 24 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Zumtobel.
Media articles that mention a CVE ID that affects a product developed by Zumtobel — matched by CVE ID, not by vendor name.