Controller Aviatrix Controller

Don't miss out!

Thousands of developers use stack.watch to stay informed.
Get an email whenever new security vulnerabilities are reported in Aviatrix Controller.

By the Year

In 2026 there have been 4 vulnerabilities in Aviatrix Controller with an average score of 7.8 out of ten. Last year, in 2025 Controller had 4 security vulnerabilities published. If vulnerabilities keep coming in at the current rate, it appears that number of security vulnerabilities in Controller in 2026 could surpass last years number. Last year, the average CVE base score was greater by 2.20




Year Vulnerabilities Average Score
2026 4 7.80
2025 4 10.00
2024 0 0.00
2023 0 0.00
2022 0 0.00
2021 2 8.65
2020 8 7.68

It may take a day or so for new Controller vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.

Recent Aviatrix Controller Security Vulnerabilities

Elevated Privilege via Unquoted Service Path in ApHidMonitorService (8.1202.1711.04)
CVE-2019-25285 7.8 - High - February 04, 2026

Alps Pointing-device Controller 8.1202.1711.04 contains an unquoted service path vulnerability in the ApHidMonitorService that allows local attackers to execute code with elevated privileges. Attackers can place a malicious executable in the service path and gain system-level access when the service restarts or the system reboots.

Unquoted Search Path or Element

Unquoted Service Path in PACService.exe (Program Access Controller 1.2.0.0)
CVE-2020-36987 7.8 - High - January 28, 2026

Program Access Controller 1.2.0.0 contains an unquoted service path vulnerability in PACService.exe that allows local attackers to execute code with elevated privileges. Attackers can exploit the unquoted path during system startup or reboot to inject and run malicious executables with LocalSystem permissions.

Unquoted Search Path or Element

Ruckus vRIoT <3.0.0.0: Hardcoded SSH creds to Docker root RCE
CVE-2025-69426 - January 09, 2026

The Ruckus vRIoT IoT Controller firmware versions prior to 3.0.0.0 (GA) contain hardcoded credentials for an operating system user account within an initialization script. The SSH service is network-accessible without IP-based restrictions. Although the configuration disables SCP and pseudo-TTY allocation, an attacker can authenticate using the hardcoded credentials and establish SSH local port forwarding to access the Docker socket. By mounting the host filesystem via Docker, an attacker can escape the container and execute arbitrary OS commands as root on the underlying vRIoT controller, resulting in complete system compromise.

Incorrect Permission Assignment for Critical Resource

Ruckus vRIoT Controller <3.0.0 Root Cmd Exec via TOTP over TCP 2004
CVE-2025-69425 - January 09, 2026

The Ruckus vRIoT IoT Controller firmware versions prior to 3.0.0.0 (GA) expose a command execution service on TCP port 2004 running with root privileges. Authentication to this service relies on a hardcoded Time-based One-Time Password (TOTP) secret and an embedded static token. An attacker who extracts these credentials from the appliance or a compromised device can generate valid authentication tokens and execute arbitrary OS commands with root privileges, resulting in complete system compromise.

Missing Authentication for Critical Function

Tinycontrol LC v1.58a: Unauth. Config Backup Download Exposing Credentials
CVE-2023-53739 - December 09, 2025

Tinycontrol LAN Controller v3 LK3 version 1.58a contains an unauthenticated vulnerability that allows remote attackers to download configuration backup files containing sensitive credentials. Attackers can retrieve the lk3_settings.bin file and extract base64-encoded user and admin passwords without authentication.

Password in Configuration File

Aviatrix Controller <7.1.4208,7.2.5090,8.0.0 - No Rate Limiting on Reset PIN(BF)
CVE-2025-2171 - June 23, 2025

Aviatrix Controller versions prior to 7.1.4208, 7.2.5090, and 8.0.0 do not enforce rate limiting on password reset attempts, allowing adversaries to brute force guess the 6-digit password reset PIN

Aquatronica Controller Sys <=5.1.6 & <=2.0: tcp.php ID Exposes Admin creds
CVE-2025-25037 - June 20, 2025

An information disclosure vulnerability exists in Aquatronica Controller System firmware versions <= 5.1.6 and web interface versions <= 2.0. The tcp.php endpoint fails to restrict unauthenticated access, allowing remote attackers to issue crafted POST requests and retrieve sensitive configuration data, including plaintext administrative credentials. Exploitation of this flaw can lead to full compromise of the system, enabling unauthorized manipulation of connected devices and aquarium parameters.

Information Disclosure

Aviatrix Controller <=7.1.4191 Cmd Inject via /v1/api (CVE-2024-50603)
CVE-2024-50603 10 - Critical - January 08, 2025

An issue was discovered in Aviatrix Controller before 7.1.4191 and 7.2.x before 7.2.4996. Due to the improper neutralization of special elements used in an OS command, an unauthenticated attacker is able to execute arbitrary code. Shell metacharacters can be sent to /v1/api in cloud_type for list_flightpath_destination_instances, or src_cloud_type for flightpath_connection_test.

Shell injection

An issue was discovered in Aviatrix Controller 6.x before 6.5-1804.1922
CVE-2021-40870 9.8 - Critical - September 13, 2021

An issue was discovered in Aviatrix Controller 6.x before 6.5-1804.1922. Unrestricted upload of a file with a dangerous type is possible, which allows an unauthenticated user to execute arbitrary code via directory traversal.

Insecure File Permissions exist in Aviatrix Controller 5.3.1516
CVE-2020-27568 7.5 - High - April 21, 2021

Insecure File Permissions exist in Aviatrix Controller 5.3.1516. Several world writable files and directories were found in the controller resource. Note: All Aviatrix appliances are fully encrypted. This is an extra layer of security.

Incorrect Permission Assignment for Critical Resource

An issue was discovered in Aviatrix Controller before R5.4.1290
CVE-2020-26549 7.5 - High - November 17, 2020

An issue was discovered in Aviatrix Controller before R5.4.1290. The htaccess protection mechanism to prevent requests to directories can be bypassed for file downloading.

Files or Directories Accessible to External Parties

An issue was discovered in Aviatrix Controller before R6.0.2483
CVE-2020-26553 9.8 - Critical - November 17, 2020

An issue was discovered in Aviatrix Controller before R6.0.2483. Several APIs contain functions that allow arbitrary files to be uploaded to the web tree.

Unrestricted File Upload

An issue was discovered in Aviatrix Controller before R6.0.2483
CVE-2020-26552 7.5 - High - November 17, 2020

An issue was discovered in Aviatrix Controller before R6.0.2483. Multiple executable files, that implement API endpoints, do not require a valid session ID for access.

Inadequate Encryption Strength

An issue was discovered in Aviatrix Controller before R5.3.1151
CVE-2020-26551 7.5 - High - November 17, 2020

An issue was discovered in Aviatrix Controller before R5.3.1151. Encrypted key values are stored in a readable file.

Cleartext Storage of Sensitive Information

An issue was discovered in Aviatrix Controller before R5.3.1151
CVE-2020-26550 7.5 - High - November 17, 2020

An issue was discovered in Aviatrix Controller before R5.3.1151. An encrypted file containing credentials to unrelated systems is protected by a three-character key.

Insufficiently Protected Credentials

An issue was discovered in Aviatrix Controller before R5.4.1290
CVE-2020-26548 8.8 - High - November 17, 2020

An issue was discovered in Aviatrix Controller before R5.4.1290. There is an insecure sudo rule: a user exists that can execute all commands as any user on the system.

An issue was discovered in Aviatrix Controller before 5.4.1204
CVE-2020-13413 5.3 - Medium - May 22, 2020

An issue was discovered in Aviatrix Controller before 5.4.1204. There is a Observable Response Discrepancy from the API, which makes it easier to perform user enumeration via brute force.

Side Channel Attack

An issue was discovered in Aviatrix Controller before 5.4.1204
CVE-2020-13414 7.5 - High - May 22, 2020

An issue was discovered in Aviatrix Controller before 5.4.1204. It contains credentials unused by the software.

Use of Hard-coded Credentials

Stay on top of Security Vulnerabilities

Want an email whenever new vulnerabilities are published for Aviatrix Controller or by Aviatrix? Click the Watch button to subscribe.

Aviatrix
Vendor

subscribe