Aviatrix
Don't miss out!
Thousands of developers use stack.watch to stay informed.Get an email whenever new security vulnerabilities are reported in any Aviatrix product.
RSS Feeds for Aviatrix security vulnerabilities
Create a CVE RSS feed including security vulnerabilities found in Aviatrix products with stack.watch. Just hit watch, then grab your custom RSS feed url.
Products by Aviatrix Sorted by Most Security Vulnerabilities since 2018
Known Exploited Aviatrix Vulnerabilities
The following Aviatrix vulnerabilities have been marked by CISA as Known to be Exploited by threat actors.
| Title | Description | Added |
|---|---|---|
| Aviatrix Controllers OS Command Injection Vulnerability |
Aviatrix Controllers contain an OS command injection vulnerability that could allow an unauthenticated attacker to execute arbitrary code. Shell metacharacters can be sent to /v1/api in cloud_type for list_flightpath_destination_instances, or src_cloud_type for flightpath_connection_test. CVE-2024-50603 Exploit Probability: 98.5% |
January 16, 2025 |
| Aviatrix Controller Unrestricted Upload of File |
Unrestricted upload of a file with a dangerous type is possible, which allows an unauthenticated user to execute arbitrary code via directory traversal. CVE-2021-40870 Exploit Probability: 93.0% |
January 18, 2022 |
Of the known exploited vulnerabilities above, 2 are in the top 1%, or the 99th percentile of the EPSS exploit probability rankings.
By the Year
In 2026 there have been 4 vulnerabilities in Aviatrix with an average score of 7.8 out of ten. Last year, in 2025 Aviatrix had 4 security vulnerabilities published. If vulnerabilities keep coming in at the current rate, it appears that number of security vulnerabilities in Aviatrix in 2026 could surpass last years number. Last year, the average CVE base score was greater by 2.20
| Year | Vulnerabilities | Average Score |
|---|---|---|
| 2026 | 4 | 7.80 |
| 2025 | 4 | 10.00 |
| 2024 | 0 | 0.00 |
| 2023 | 0 | 0.00 |
| 2022 | 1 | 8.80 |
| 2021 | 3 | 8.27 |
| 2020 | 9 | 7.68 |
It may take a day or so for new Aviatrix vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.
Recent Aviatrix Security Vulnerabilities
| CVE | Date | Vulnerability | Products |
|---|---|---|---|
| CVE-2019-25285 | Feb 04, 2026 |
Elevated Privilege via Unquoted Service Path in ApHidMonitorService (8.1202.1711.04)Alps Pointing-device Controller 8.1202.1711.04 contains an unquoted service path vulnerability in the ApHidMonitorService that allows local attackers to execute code with elevated privileges. Attackers can place a malicious executable in the service path and gain system-level access when the service restarts or the system reboots. |
|
| CVE-2020-36987 | Jan 28, 2026 |
Unquoted Service Path in PACService.exe (Program Access Controller 1.2.0.0)Program Access Controller 1.2.0.0 contains an unquoted service path vulnerability in PACService.exe that allows local attackers to execute code with elevated privileges. Attackers can exploit the unquoted path during system startup or reboot to inject and run malicious executables with LocalSystem permissions. |
|
| CVE-2025-69426 | Jan 09, 2026 |
Ruckus vRIoT <3.0.0.0: Hardcoded SSH creds to Docker root RCEThe Ruckus vRIoT IoT Controller firmware versions prior to 3.0.0.0 (GA) contain hardcoded credentials for an operating system user account within an initialization script. The SSH service is network-accessible without IP-based restrictions. Although the configuration disables SCP and pseudo-TTY allocation, an attacker can authenticate using the hardcoded credentials and establish SSH local port forwarding to access the Docker socket. By mounting the host filesystem via Docker, an attacker can escape the container and execute arbitrary OS commands as root on the underlying vRIoT controller, resulting in complete system compromise. |
|
| CVE-2025-69425 | Jan 09, 2026 |
Ruckus vRIoT Controller <3.0.0 Root Cmd Exec via TOTP over TCP 2004The Ruckus vRIoT IoT Controller firmware versions prior to 3.0.0.0 (GA) expose a command execution service on TCP port 2004 running with root privileges. Authentication to this service relies on a hardcoded Time-based One-Time Password (TOTP) secret and an embedded static token. An attacker who extracts these credentials from the appliance or a compromised device can generate valid authentication tokens and execute arbitrary OS commands with root privileges, resulting in complete system compromise. |
|
| CVE-2023-53739 | Dec 09, 2025 |
Tinycontrol LC v1.58a: Unauth. Config Backup Download Exposing CredentialsTinycontrol LAN Controller v3 LK3 version 1.58a contains an unauthenticated vulnerability that allows remote attackers to download configuration backup files containing sensitive credentials. Attackers can retrieve the lk3_settings.bin file and extract base64-encoded user and admin passwords without authentication. |
|
| CVE-2025-2171 | Jun 23, 2025 |
Aviatrix Controller <7.1.4208,7.2.5090,8.0.0 - No Rate Limiting on Reset PIN(BF)Aviatrix Controller versions prior to 7.1.4208, 7.2.5090, and 8.0.0 do not enforce rate limiting on password reset attempts, allowing adversaries to brute force guess the 6-digit password reset PIN |
|
| CVE-2025-25037 | Jun 20, 2025 |
Aquatronica Controller Sys <=5.1.6 & <=2.0: tcp.php ID Exposes Admin credsAn information disclosure vulnerability exists in Aquatronica Controller System firmware versions <= 5.1.6 and web interface versions <= 2.0. The tcp.php endpoint fails to restrict unauthenticated access, allowing remote attackers to issue crafted POST requests and retrieve sensitive configuration data, including plaintext administrative credentials. Exploitation of this flaw can lead to full compromise of the system, enabling unauthorized manipulation of connected devices and aquarium parameters. |
|
| CVE-2024-50603 | Jan 08, 2025 |
Aviatrix Controller <=7.1.4191 Cmd Inject via /v1/api (CVE-2024-50603)An issue was discovered in Aviatrix Controller before 7.1.4191 and 7.2.x before 7.2.4996. Due to the improper neutralization of special elements used in an OS command, an unauthenticated attacker is able to execute arbitrary code. Shell metacharacters can be sent to /v1/api in cloud_type for list_flightpath_destination_instances, or src_cloud_type for flightpath_connection_test. |
|
| CVE-2022-38368 | Aug 15, 2022 |
Aviatrix Gateway Auth Bypass Cmd Injection (6.6.5712 & <6.7.1376)An issue was discovered in Aviatrix Gateway before 6.6.5712 and 6.7.x before 6.7.1376. Because Gateway API functions mishandle authentication, an authenticated VPN user can inject arbitrary commands. |
|
| CVE-2021-40870 | Sep 13, 2021 |
An issue was discovered in Aviatrix Controller 6.x before 6.5-1804.1922An issue was discovered in Aviatrix Controller 6.x before 6.5-1804.1922. Unrestricted upload of a file with a dangerous type is possible, which allows an unauthenticated user to execute arbitrary code via directory traversal. |
|