← Back

Controlbyweb

controlbyweb

5 CVEs • 12 products

Products (12)

Click to collapse
Toggle
X 400 Firmware
x-400_firmware
X 320m I
x-320m-i
X 600m
x-600m
X 400
x-400
X 332 24i
x-332-24i
X 301 I
x-301-i
X 301 24i
x-301-24i

CVEs (5)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Controlbyweb
3X 301 24i Firmware
X 301 I FirmwareX 332 24i Firmware
Nov 21, 2024
Dec 7, 2023
N/A· v4
5.4 MEDIUM· v3
N/A· v2
The affected ControlByWeb Relay products are vulnerable to a stored cross-site scripting vulnerability, which could allow an attacker to inject arbitrary scripts into the endpoint of a web interface that could run malic...Show more
The affected ControlByWeb Relay products are vulnerable to a stored cross-site scripting vulnerability, which could allow an attacker to inject arbitrary scripts into the endpoint of a web interface that could run malicious javascript code during a user's session. Show less
1Controlbyweb
1X 400 Firmware
Nov 21, 2024
Feb 13, 2023
N/A· v4
6.1 MEDIUM· v3
N/A· v2
Control By Web X-400 devices are vulnerable to a cross-site scripting attack, which could result in private and session information being transferred to the attacker.
1Controlbyweb
1X 600m Firmware
Nov 21, 2024
Feb 13, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Control By Web X-600M devices run Lua scripts and are vulnerable to code injection, which could allow an attacker to remotely execute arbitrary code.
1Controlbyweb
1X 320m I Firmware
Nov 21, 2024
Mar 21, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
A stored cross-site scripting (XSS) issue was discovered in ControlByWeb X-320M-I Web-Enabled Instrumentation-Grade Data Acquisition module 1.05 with firmware revision v1.05. An authenticated user can inject arbitrary sc...Show more
A stored cross-site scripting (XSS) issue was discovered in ControlByWeb X-320M-I Web-Enabled Instrumentation-Grade Data Acquisition module 1.05 with firmware revision v1.05. An authenticated user can inject arbitrary script via setup.html in the web interface.Show less
1Controlbyweb
1X 320m I Firmware
Nov 21, 2024
Mar 21, 2019
N/A· v4
6.5 MEDIUM· v3
6.8 MEDIUM· v2
A Denial of Service (DOS) issue was discovered in ControlByWeb X-320M-I Web-Enabled Instrumentation-Grade Data Acquisition module 1.05 with firmware revision v1.05. An authenticated user can configure invalid network set...Show more
A Denial of Service (DOS) issue was discovered in ControlByWeb X-320M-I Web-Enabled Instrumentation-Grade Data Acquisition module 1.05 with firmware revision v1.05. An authenticated user can configure invalid network settings, stopping TCP based communications to the device. A physical factory reset is required to restore the device to an operational state.Show less