Aviatrix Aviatrix

Don't miss out!

Thousands of developers use stack.watch to stay informed.
Get an email whenever new security vulnerabilities are reported in any Aviatrix product.

RSS Feeds for Aviatrix security vulnerabilities

Create a CVE RSS feed including security vulnerabilities found in Aviatrix products with stack.watch. Just hit watch, then grab your custom RSS feed url.

Products by Aviatrix Sorted by Most Security Vulnerabilities since 2018

Aviatrix Controller18 vulnerabilities

Aviatrix Gateway2 vulnerabilities

Aviatrix Openvpn2 vulnerabilities

Aviatrix Vpn Client1 vulnerability

Known Exploited Aviatrix Vulnerabilities

The following Aviatrix vulnerabilities have been marked by CISA as Known to be Exploited by threat actors.

Title Description Added
Aviatrix Controllers OS Command Injection Vulnerability Aviatrix Controllers contain an OS command injection vulnerability that could allow an unauthenticated attacker to execute arbitrary code. Shell metacharacters can be sent to /v1/api in cloud_type for list_flightpath_destination_instances, or src_cloud_type for flightpath_connection_test.
CVE-2024-50603 Exploit Probability: 98.5%
January 16, 2025
Aviatrix Controller Unrestricted Upload of File Unrestricted upload of a file with a dangerous type is possible, which allows an unauthenticated user to execute arbitrary code via directory traversal.
CVE-2021-40870 Exploit Probability: 93.0%
January 18, 2022

Of the known exploited vulnerabilities above, 2 are in the top 1%, or the 99th percentile of the EPSS exploit probability rankings.

By the Year

In 2026 there have been 4 vulnerabilities in Aviatrix with an average score of 7.8 out of ten. Last year, in 2025 Aviatrix had 4 security vulnerabilities published. If vulnerabilities keep coming in at the current rate, it appears that number of security vulnerabilities in Aviatrix in 2026 could surpass last years number. Last year, the average CVE base score was greater by 2.20




Year Vulnerabilities Average Score
2026 4 7.80
2025 4 10.00
2024 0 0.00
2023 0 0.00
2022 1 8.80
2021 3 8.27
2020 9 7.68

It may take a day or so for new Aviatrix vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.

Recent Aviatrix Security Vulnerabilities

CVE Date Vulnerability Products
CVE-2019-25285 Feb 04, 2026
Elevated Privilege via Unquoted Service Path in ApHidMonitorService (8.1202.1711.04) Alps Pointing-device Controller 8.1202.1711.04 contains an unquoted service path vulnerability in the ApHidMonitorService that allows local attackers to execute code with elevated privileges. Attackers can place a malicious executable in the service path and gain system-level access when the service restarts or the system reboots.
Controller
CVE-2020-36987 Jan 28, 2026
Unquoted Service Path in PACService.exe (Program Access Controller 1.2.0.0) Program Access Controller 1.2.0.0 contains an unquoted service path vulnerability in PACService.exe that allows local attackers to execute code with elevated privileges. Attackers can exploit the unquoted path during system startup or reboot to inject and run malicious executables with LocalSystem permissions.
Controller
CVE-2025-69426 Jan 09, 2026
Ruckus vRIoT <3.0.0.0: Hardcoded SSH creds to Docker root RCE The Ruckus vRIoT IoT Controller firmware versions prior to 3.0.0.0 (GA) contain hardcoded credentials for an operating system user account within an initialization script. The SSH service is network-accessible without IP-based restrictions. Although the configuration disables SCP and pseudo-TTY allocation, an attacker can authenticate using the hardcoded credentials and establish SSH local port forwarding to access the Docker socket. By mounting the host filesystem via Docker, an attacker can escape the container and execute arbitrary OS commands as root on the underlying vRIoT controller, resulting in complete system compromise.
Controller
CVE-2025-69425 Jan 09, 2026
Ruckus vRIoT Controller <3.0.0 Root Cmd Exec via TOTP over TCP 2004 The Ruckus vRIoT IoT Controller firmware versions prior to 3.0.0.0 (GA) expose a command execution service on TCP port 2004 running with root privileges. Authentication to this service relies on a hardcoded Time-based One-Time Password (TOTP) secret and an embedded static token. An attacker who extracts these credentials from the appliance or a compromised device can generate valid authentication tokens and execute arbitrary OS commands with root privileges, resulting in complete system compromise.
Controller
CVE-2023-53739 Dec 09, 2025
Tinycontrol LC v1.58a: Unauth. Config Backup Download Exposing Credentials Tinycontrol LAN Controller v3 LK3 version 1.58a contains an unauthenticated vulnerability that allows remote attackers to download configuration backup files containing sensitive credentials. Attackers can retrieve the lk3_settings.bin file and extract base64-encoded user and admin passwords without authentication.
Controller
CVE-2025-2171 Jun 23, 2025
Aviatrix Controller <7.1.4208,7.2.5090,8.0.0 - No Rate Limiting on Reset PIN(BF) Aviatrix Controller versions prior to 7.1.4208, 7.2.5090, and 8.0.0 do not enforce rate limiting on password reset attempts, allowing adversaries to brute force guess the 6-digit password reset PIN
Controller
CVE-2025-25037 Jun 20, 2025
Aquatronica Controller Sys <=5.1.6 & <=2.0: tcp.php ID Exposes Admin creds An information disclosure vulnerability exists in Aquatronica Controller System firmware versions <= 5.1.6 and web interface versions <= 2.0. The tcp.php endpoint fails to restrict unauthenticated access, allowing remote attackers to issue crafted POST requests and retrieve sensitive configuration data, including plaintext administrative credentials. Exploitation of this flaw can lead to full compromise of the system, enabling unauthorized manipulation of connected devices and aquarium parameters.
Controller
CVE-2024-50603 Jan 08, 2025
Aviatrix Controller <=7.1.4191 Cmd Inject via /v1/api (CVE-2024-50603) An issue was discovered in Aviatrix Controller before 7.1.4191 and 7.2.x before 7.2.4996. Due to the improper neutralization of special elements used in an OS command, an unauthenticated attacker is able to execute arbitrary code. Shell metacharacters can be sent to /v1/api in cloud_type for list_flightpath_destination_instances, or src_cloud_type for flightpath_connection_test.
Controller
CVE-2022-38368 Aug 15, 2022
Aviatrix Gateway Auth Bypass Cmd Injection (6.6.5712 & <6.7.1376) An issue was discovered in Aviatrix Gateway before 6.6.5712 and 6.7.x before 6.7.1376. Because Gateway API functions mishandle authentication, an authenticated VPN user can inject arbitrary commands.
Gateway
CVE-2021-40870 Sep 13, 2021
An issue was discovered in Aviatrix Controller 6.x before 6.5-1804.1922 An issue was discovered in Aviatrix Controller 6.x before 6.5-1804.1922. Unrestricted upload of a file with a dangerous type is possible, which allows an unauthenticated user to execute arbitrary code via directory traversal.
Controller
Built by Foundeo Inc., with data from the National Vulnerability Database (NVD). Privacy Policy. Use of this site is governed by the Legal Terms
Disclaimer
CONTENT ON THIS WEBSITE IS PROVIDED ON AN "AS IS" BASIS AND DOES NOT IMPLY ANY KIND OF GUARANTEE OR WARRANTY, INCLUDING THE WARRANTIES OF MERCHANTABILITY OR FITNESS FOR A PARTICULAR USE. YOUR USE OF THE INFORMATION ON THE DOCUMENT OR MATERIALS LINKED FROM THE DOCUMENT IS AT YOUR OWN RISK. Always check with your vendor for the most up to date, and accurate information.