Ip-comCVEs & Vulnerabilities

21 CVEs affecting Ip-com products, tracked from the National Vulnerability Database, with CVSS/EPSS scores and exploitation status.

Most Affected Products

m50 15m50 firmware 15ew9 5ew9 firmware 5w30ap 1w30ap firmware 1
CVE-2026-2017CRITICAL

A vulnerability was detected in IP-COM W30AP up to 1.0.0.11(1340). Affected by this issue is the function R7WebsSecurityHandler of the file /goform/wx3auth of the component POST Request Handler. The manipulation of the argument data results in stack-based buffer overflow. The attack may be performed from remote. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

6 Feb 2026
9.8
CVSS
CVE-2022-45721CRITICAL

IP-COM M50 V15.11.0.33(10768) was discovered to contain a buffer overflow via the picName parameter in the formDelWewifiPic function.

23 Dec 2022
9.8
CVSS
CVE-2022-45720CRITICAL

IP-COM M50 V15.11.0.33(10768) was discovered to contain multiple buffer overflows via the ip, mac, and remark parameters in the formIPMacBindModify function.

23 Dec 2022
9.8
CVSS
CVE-2022-45719CRITICAL

IP-COM M50 V15.11.0.33(10768) was discovered to contain a buffer overflow via the gotoUrl parameter in the formPortalAuth function.

23 Dec 2022
9.8
CVSS
CVE-2022-45718CRITICAL

IP-COM M50 V15.11.0.33(10768) was discovered to contain a buffer overflow via the rules parameter in the formIPMacBindAdd function.

23 Dec 2022
9.8
CVSS
CVE-2022-45717CRITICAL

IP-COM M50 V15.11.0.33(10768) was discovered to contain a command injection vulnerability via the usbPartitionName parameter in the formSetUSBPartitionUmount function. This vulnerability is exploited via a crafted GET request.

23 Dec 2022
9.8
CVSS
CVE-2022-45716CRITICAL

IP-COM M50 V15.11.0.33(10768) was discovered to contain a buffer overflow via the indexSet parameter in the formIPMacBindDel function.

23 Dec 2022
9.8
CVSS
CVE-2022-45715CRITICAL

IP-COM M50 V15.11.0.33(10768) was discovered to contain multiple buffer overflows via the pLanPortRange and pWanPortRange parameters in the formSetPortMapping function.

23 Dec 2022
9.8
CVSS
CVE-2022-45714CRITICAL

IP-COM M50 V15.11.0.33(10768) was discovered to contain a buffer overflow via the indexSet parameter in the formQOSRuleDel function.

23 Dec 2022
9.8
CVSS
CVE-2022-45712CRITICAL

IP-COM M50 V15.11.0.33(10768) was discovered to contain a buffer overflow via the rules parameter in the formAddDnsForward function.

23 Dec 2022
9.8
CVSS
CVE-2022-45711CRITICAL

IP-COM M50 V15.11.0.33(10768) was discovered to contain a command injection vulnerability via the hostname parameter in the formSetNetCheckTools function.

23 Dec 2022
9.8
CVSS
CVE-2022-45710CRITICAL

IP-COM M50 V15.11.0.33(10768) was discovered to contain multiple buffer overflows via the pEnable, pLevel, and pModule parameters in the formSetDebugCfg function.

23 Dec 2022
9.8
CVSS
CVE-2022-45709CRITICAL

IP-COM M50 V15.11.0.33(10768) was discovered to contain multiple command injection vulnerabilities via the pEnable, pLevel, and pModule parameters in the formSetDebugCfg function.

23 Dec 2022
9.8
CVSS
CVE-2022-45708CRITICAL

IP-COM M50 V15.11.0.33(10768) was discovered to contain a buffer overflow via the sPortMapIndex parameter in the formDelPortMapping function.

23 Dec 2022
9.8
CVSS
CVE-2022-45707CRITICAL

IP-COM M50 V15.11.0.33(10768) was discovered to contain a buffer overflow via the rules parameter in the formAddDnsHijack function.

23 Dec 2022
9.8
CVSS
CVE-2022-45706CRITICAL

IP-COM M50 V15.11.0.33(10768) was discovered to contain a buffer overflow via the hostname parameter in the formSetNetCheckTools function.

23 Dec 2022
9.8
CVSS
CVE-2022-45005CRITICAL

IP-COM EW9 V15.11.0.14(9732) was discovered to contain a command injection vulnerability in the cmd_get_ping_output function.

13 Dec 2022
9.8
CVSS
CVE-2022-43367CRITICAL

IP-COM EW9 V15.11.0.14(9732) was discovered to contain a command injection vulnerability in the formSetDebugCfg function.

27 Oct 2022
9.8
CVSS
CVE-2022-43366HIGH

IP-COM EW9 V15.11.0.14(9732) allows unauthenticated attackers to access sensitive information via the checkLoginUser, ate, telnet, version, setDebugCfg, and boot interfaces.

27 Oct 2022
7.5
CVSS
CVE-2022-43365HIGH

IP-COM EW9 V15.11.0.14(9732) was discovered to contain a buffer overflow in the formSetDebugCfg function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted string.

27 Oct 2022
7.5
CVSS
CVE-2022-43364HIGH

An access control issue in the password reset page of IP-COM EW9 V15.11.0.14(9732) allows unauthenticated attackers to arbitrarily change the admin password.

27 Oct 2022
7.5
CVSS
← PrevPage 1 / 1Next →
Ip-com CVEs & Vulnerabilities — 21 Tracked