CVE Tools

Ctrlx Hmi Web Panel - WR21 (WR2115)

9 CVEs tracked. None of them is in CISA KEV.

This hub aggregates every CVE we track for Ctrlx Hmi Web Panel - WR21 (WR2115), a product in the ics ot iot space. Use it to gauge the current risk picture and drill into individual advisories.

Ctrlx Hmi Web Panel - WR21 (WR2115) CVEs per month

Oct 2024 to Sep 2026. Point at a month, or focus the strip and use the arrow keys.
Ctrlx Hmi Web Panel - WR21 (WR2115) CVEs per month
MonthCVEs
2024-100
2024-110
2024-120
2025-010
2025-020
2025-030
2025-040
2025-050
2025-060
2025-070
2025-080
2025-090
2025-100
2025-110
2025-120
2026-010
2026-020
2026-030
2026-040
2026-050
2026-060
2026-070
2026-080
2026-090

Severity

How the 9 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.

  • High889%
  • Medium111%

Latest CVEs

The 9 most recently published vulnerabilities affecting Ctrlx Hmi Web Panel - WR21 (WR2115).

  1. CVE-2023-46102The Android Client application, when enrolled to the AppHub server, connects to an MQTT broker to exchange messages and receive commands to execute on the HMI device. The protocol builds on top o...8.8
  2. CVE-2023-45851The Android Client application, when enrolled to the AppHub server,connects to an MQTT broker without enforcing any server authentication.  This issue allows an attacker to force the Android ...8.8
  3. CVE-2023-45321The Android Client application, when enrolled with the define method 1 (the user manually inserts the server ip address), use HTTP protocol to retrieve sensitive information (ip address and creden...8.3
  4. CVE-2023-45220The Android Client application, when enrolled with the define method 1(the user manually inserts the server ip address), use HTTP protocol to retrieve sensitive information (ip address and credent...8.8
  5. CVE-2023-41372The vulnerability allows an unprivileged (untrusted) third- party application to arbitrary modify the server settings of the Android Client application, inducing it to connect to an attacker - cont...7.8
  6. CVE-2023-41960The vulnerability allows an unprivileged(untrusted) third-party application to interact with a content-provider unsafely exposed by the Android Agent application, potentially modifying sensitive se...7.1
  7. CVE-2023-41255The vulnerability allows an unprivileged user with access to the subnet of the TPC-110W device to gain a root shell on the device itself abusing the lack of authentication of the ‘su’ binary ...8.8
  8. CVE-2023-43488The vulnerability allows a low privileged (untrusted) application to modify a critical system property that should be denied, in order to enable the ADB (Android Debug Bridge) protocol to be expos...7.9
  9. CVE-2023-45844The vulnerability allows a low privileged user that have access to the device when locked in Kiosk mode to install an arbitrary Android application and leverage it to have access to critical device...6.8

Product grouping is registry-driven, with AI assist and human review. How it works

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store