-Infinity
0

Vendor Risk Score

See how wut compares to other vendors in security performance

View Risk Score →

Software

wut com-server 20ma firmware
4
wut com-server highspeed 100basefx firmware
4
wut com-server highspeed compact
4
wut com-server highspeed compact firmware
4
wut com-server highspeed industry firmware
4
wut com-server highspeed isolated
4
wut com-server highspeed isolated firmware
4
wut com-server highspeed lc firmware
4
wut com-server highspeed oem firmware
4
wut com-server highspeed office 1port firmware
4
wut com-server highspeed office 4port firmware
4
wut com-server highspeed poe
4
wut com-server highspeed poe 3x isolated firmware
4
wut com-server highspeed poe firmware
4
wut com-server highspeed ul
4
wut com-server highspeed ul firmware
4
wut at-modem-emulator
3
wut at-modem-emulator firmware
3
wut com-server 20ma
3
wut com-server \+\+
3
wut com-server \+\+ firmware
3
wut com-server highspeed 100basefx
3
wut com-server highspeed 100baselx
3
wut com-server highspeed 100baselx firmware
3
wut com-server highspeed 19\" 1port
3
wut com-server highspeed 19\" 1port firmware
3
wut com-server highspeed 19\" 4port
3
wut com-server highspeed 19\" 4port firmware
3
wut com-server highspeed industry
3
wut com-server highspeed lc
3
wut com-server highspeed oem
3
wut com-server highspeed office 1port
3
wut com-server highspeed office 4port
3
wut com-server highspeed poe 3x isolated
3
wut com port redirector plug & play
1
wut com-server ++
1
wut com-server ++ firmware
1
wut com-server highspeed
1
wut com-server highspeed 19" 1port
1
wut com-server highspeed 19" 1port firmware
1
wut com-server highspeed 19" 4port
1
wut com-server highspeed 19" 4port firmware
1
wut com-server highspeed 1port firmware
1
wut opc server
1
Severity
9.8
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Multiple W&T products of the ComServer Series are prone to an authentication bypass. An unathenticated remote attacker, can log in without knowledge of the password by crafting a modified HTTP GET Request.

First published (updated )
Severity
5.4
XSS
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

Multiple W&T Products of the ComServer Series are prone to an XSS attack. An authenticated remote Attacker can execute arbitrary web scripts or HTML via a crafted payload injected into the title of the configuration webpage

First published (updated )
Severity
8.8
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Multiple W&T products of the Comserver Series use a small number space for allocating sessions ids. After login of an user an unathenticated remote attacker can brute force the users session id and get access to his account on the the device. As the user needs to log in for the attack to be successful a user interaction is required.

First published (updated )
Severity
8
CVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Multiple Wiesemann&Theis products of the ComServer Series are prone to an authentication bypass through IP spoofing. After a user logged in to the WBM of the Com-Server an unauthenticated attacker in the same subnet can obtain the session ID and through IP spoofing change arbitrary settings by crafting modified HTTP Get requests. This may result in a complete takeover of the device.

First published (updated )
Severity
7.8
EPSS
0.04%
AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

A local attacker can gain administrative privileges by inserting an executable file in the path of the affected product.

First published (updated )

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203