WM2 Firmware
21 CVEs tracked. None of them is in CISA KEV.
This hub aggregates every CVE we track for WM2 Firmware, a product in the ics ot iot space. Use it to gauge the current risk picture and drill into individual advisories.
WM2 Firmware CVEs per month
| Month | CVEs |
|---|---|
| 2024-10 | 0 |
| 2024-11 | 0 |
| 2024-12 | 0 |
| 2025-01 | 0 |
| 2025-02 | 0 |
| 2025-03 | 0 |
| 2025-04 | 0 |
| 2025-05 | 0 |
| 2025-06 | 0 |
| 2025-07 | 0 |
| 2025-08 | 0 |
| 2025-09 | 0 |
| 2025-10 | 0 |
| 2025-11 | 0 |
| 2025-12 | 21 |
| 2026-01 | 0 |
| 2026-02 | 0 |
| 2026-03 | 0 |
| 2026-04 | 0 |
| 2026-05 | 0 |
| 2026-06 | 0 |
| 2026-07 | 0 |
| 2026-08 | 0 |
| 2026-09 | 0 |
Severity
How the 21 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.
- Critical8
- High12
- Medium1
Latest CVEs
The 15 most recently published vulnerabilities affecting WM2 Firmware.
- CVE-2022-50796SOUND4 IMPACT/FIRST/PULSE/Eco <=2.x Unauthenticated Remote Code Execution via upload.cgi9.8
- CVE-2022-50795SOUND4 IMPACT/FIRST/PULSE/Eco <=2.x Conditional Command Injection via traceroute.php7.8
- CVE-2022-50794SOUND4 IMPACT/FIRST/PULSE/Eco <=2.x Unauthenticated Command Injection via Username9.8
- CVE-2022-50793SOUND4 IMPACT/FIRST/PULSE/Eco <=2.x Authenticated Command Injection via www-data-handler.php8.8
- CVE-2022-50790SOUND4 IMPACT/FIRST/PULSE/Eco <=2.x Unauthenticated Radio Stream Disclosure7.5
- CVE-2022-50792SOUND4 IMPACT/FIRST/PULSE/Eco <=2.x Unauthenticated File Disclosure Vulnerability7.5
- CVE-2022-50791SOUND4 IMPACT/FIRST/PULSE/Eco <=2.x Conditional Command Injection via ping.php7.8
- CVE-2022-50789SOUND4 IMPACT/FIRST/PULSE/Eco <=2.x Conditional Command Injection via dns.php7.8
- CVE-2022-50788SOUND4 IMPACT/FIRST/PULSE/Eco <=2.x Information Disclosure via Log Directory7.5
- CVE-2022-50696SOUND4 IMPACT/FIRST/PULSE/Eco <=2.x Hardcoded Credentials Authentication Bypass9.8
- CVE-2022-50787SOUND4 IMPACT/FIRST/PULSE/Eco <=2.x Unauthenticated Stored Cross-Site Scripting7.2
- CVE-2022-50694SOUND4 IMPACT/FIRST/PULSE/Eco <=2.x SQL Injection via Username Parameter9.8
- CVE-2022-50695SOUND4 IMPACT/FIRST/PULSE/Eco <=2.x ICMP Flood Attack via Network Commands7.5
- CVE-2022-50692SOUND4 IMPACT/FIRST/PULSE/Eco <=2.x Insufficient Session Expiration Vulnerability7.5
- CVE-2023-53963SOUND4 IMPACT/FIRST/PULSE/Eco v2.x Unauthenticated Remote Command Injection9.8
Product grouping is registry-driven, with AI assist and human review. How it works