CVE Tools

Rexroth

35 CVEs tracked since 2021. Since Oct 2021, none of them reached CISA KEV.

Rexroth CVEs per month

Oct 2021 to Jan 2024. Point at a month, or focus the strip and use the arrow keys.
Rexroth CVEs per month, with the share now in CISA KEV
MonthCVEsIn CISA KEV
2021-1040
2021-11null or fewer
2021-12null or fewer
2022-01null or fewer
2022-02null or fewer
2022-03null or fewer
2022-04null or fewer
2022-05null or fewer
2022-06null or fewer
2022-07null or fewer
2022-08null or fewer
2022-09null or fewer
2022-10null or fewer
2022-11null or fewer
2022-12null or fewer
2023-01null or fewer
2023-02null or fewer
2023-03null or fewer
2023-04null or fewer
2023-05null or fewer
2023-06null or fewer
2023-07null or fewer
2023-08null or fewer
2023-09null or fewer
2023-1060
2023-11null or fewer
2023-12null or fewer
2024-01250

Products

The products that kept showing up in Rexroth's monthly top three, with their CVEs summed over those months.

  1. Nexo Cordless Nutrunner NXA011S-36V (0608842011)251 month
  2. Nexo Cordless Nutrunner NXA011S-36V-B (0608842012)251 month
  3. Nexo Cordless Nutrunner NXA015S-36V (0608842001)251 month
  4. Ctrlx Hmi Web Panel - WR21 (WR2107)61 month
  5. Ctrlx Hmi Web Panel - WR21 (WR2110)61 month
  6. Ctrlx Hmi Web Panel - WR21 (WR2115)61 month
  7. Indramotion Mlc L20, L4031 month
  8. Indramotion Mlc Indramotion Xlc11 month
  9. Indramotion Mlc L25, L45, L65, L75, L85, Xm21, Xm22, XM41 and XM42 Indramotion Xlc11 month

Latest CVEs

The 15 most recently published vulnerabilities affecting Rexroth.

  1. CVE-2023-48266The vulnerability allows an unauthenticated remote attacker to perform a Denial-of-Service (DoS) attack or, possibly, obtain Remote Code Execution (RCE) via a crafted network request.8.1
  2. CVE-2023-48265The vulnerability allows an unauthenticated remote attacker to perform a Denial-of-Service (DoS) attack or, possibly, obtain Remote Code Execution (RCE) via a crafted network request.8.1
  3. CVE-2023-48264The vulnerability allows an unauthenticated remote attacker to perform a Denial-of-Service (DoS) attack or, possibly, obtain Remote Code Execution (RCE) via a crafted network request.8.1
  4. CVE-2023-48263The vulnerability allows an unauthenticated remote attacker to perform a Denial-of-Service (DoS) attack or, possibly, obtain Remote Code Execution (RCE) via a crafted network request.8.1
  5. CVE-2023-48262The vulnerability allows an unauthenticated remote attacker to perform a Denial-of-Service (DoS) attack or, possibly, obtain Remote Code Execution (RCE) via a crafted network request.8.1
  6. CVE-2023-48261The vulnerability allows a remote unauthenticated attacker to read arbitrary content of the results database via a crafted HTTP request.5.3
  7. CVE-2023-48260The vulnerability allows a remote unauthenticated attacker to read arbitrary content of the results database via a crafted HTTP request.5.3
  8. CVE-2023-48259The vulnerability allows a remote unauthenticated attacker to read arbitrary content of the results database via a crafted HTTP request.5.3
  9. CVE-2023-48258The vulnerability allows a remote attacker to delete arbitrary files on the file system via a crafted URL or HTTP request through a victim’s session.5.5
  10. CVE-2023-48257The vulnerability allows a remote attacker to access sensitive data inside exported packages or obtain up to Remote Code Execution (RCE) with root privileges on the device. The vulnerability can be...7.8
  11. CVE-2023-48256The vulnerability allows a remote attacker to inject arbitrary HTTP response headers or manipulate HTTP response bodies inside a victim’s session via a crafted URL or HTTP request.5.3
  12. CVE-2023-48255The vulnerability allows an unauthenticated remote attacker to send malicious network requests containing arbitrary client-side script code and obtain its execution inside a victim’s session via ...6.3
  13. CVE-2023-48254The vulnerability allows a remote attacker to inject and execute arbitrary client-side script code inside a victim’s session via a crafted URL or HTTP request.5.3
  14. CVE-2023-48253The vulnerability allows a remote authenticated attacker to read or update arbitrary content of the authentication database via a crafted HTTP request. By abusing this vulnerability it is possible...8.8
  15. CVE-2023-48252The vulnerability allows an authenticated remote attacker to perform actions exceeding their authorized access via crafted HTTP requests.8.8

The record

Peak rank
#41 in Jan 2024
Busiest month shown
Jan 2024, 25 CVEs
Months with a KEV entry
0 since Oct 2021
Monthly snapshots
3 since 2021
Rexroth's full record, month by month

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store