Cassianetworks

    Dashboard / Vendors

    Products: 5
    Vulnerabilities: 5
    Known Exploited: 0
    1
    Critical Level Threats
    2
    High Level Threats
    2
    Medium Level Threats
    0
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2023-31446

    In Cassia Gateway firmware XC1000_2.1.1.2303082218 and XC2000_2.1.1.2303090947, the queueUrl parameter in /bypass/config is not sanitized. This leads to injecting Bash code and executing it with root privileges on device startup.

    Last Modified: Jun 20, 2025
    Published: Jan 10, 2024

    CVE-2023-35794

    An issue was discovered in Cassia Access Controller 2.1.1.2303271039. The Web SSH terminal endpoint (spawned console) can be accessed without authentication. Specifically, there is no session cookie validation on the Access Controller; instead, there is only Basic Authentication to the SSH console.

    Last Modified: Nov 21, 2024
    Published: Oct 27, 2023

    CVE-2023-35793

    An issue was discovered in Cassia Access Controller 2.1.1.2303271039. Establishing a web SSH session to gateways is vulnerable to Cross Site Request Forgery (CSRF) attacks.

    Last Modified: Nov 21, 2024
    Published: Sep 26, 2023

    CVE-2023-31445

    Cassia Access controller before 2.1.1.2203171453, was discovered to have a unprivileged -information disclosure vulnerability that allows read-only users have the ability to enumerate all other users and discover e-mail addresses, phone numbers, and privileges of all other users.

    Last Modified: Nov 21, 2024
    Published: May 11, 2023

    CVE-2021-22685

    Cassia Networks Access Controller Path Traversal

    Last Modified: Apr 16, 2025
    Published: Oct 14, 2022
    Items Per Page
    Cassianetworks Vulnerabilities & Security CVEs | CVE-DB