generex CVE Vulnerabilities & Metrics

Focus on generex vulnerabilities and metrics.

Last updated: 08 Mar 2025, 23:25 UTC

About generex Security Exposure

This page consolidates all known Common Vulnerabilities and Exposures (CVEs) associated with generex. We track both calendar-based metrics (using fixed periods) and rolling metrics (using gliding windows) to give you a comprehensive view of security trends and risk evolution. Use these insights to assess risk and plan your patching strategy.

For a broader perspective on cybersecurity threats, explore the comprehensive list of CVEs by vendor and product. Stay updated on critical vulnerabilities affecting major software and hardware providers.

Global CVE Overview

Total generex CVEs: 10
Earliest CVE date: 27 Apr 2020, 14:15 UTC
Latest CVE date: 28 Sep 2023, 14:15 UTC

Latest CVE reference: CVE-2022-47187

Rolling Stats

30-day Count (Rolling): 0
365-day Count (Rolling): 0

Calendar-based Variation

Calendar-based Variation compares a fixed calendar period (e.g., this month versus the same month last year), while Rolling Growth Rate uses a continuous window (e.g., last 30 days versus the previous 30 days) to capture trends independent of calendar boundaries.

Variations & Growth

Month Variation (Calendar): 0%
Year Variation (Calendar): -100.0%

Month Growth Rate (30-day Rolling): 0.0%
Year Growth Rate (365-day Rolling): -100.0%

Monthly CVE Trends (current vs previous Year)

Annual CVE Trends (Last 20 Years)

Critical generex CVEs (CVSS ≥ 9) Over 20 Years

CVSS Stats

Average CVSS: 0.95

Max CVSS: 5.5

Critical CVEs (≥9): 0

CVSS Range vs. Count

Range Count
0.0-3.9 8
4.0-6.9 2
7.0-8.9 0
9.0-10.0 0

CVSS Distribution Chart

Top 5 Highest CVSS generex CVEs

These are the five CVEs with the highest CVSS scores for generex, sorted by severity first and recency.

All CVEs for generex

CVE-2022-47187 generex vulnerability CVSS: 0 28 Sep 2023, 14:15 UTC

There is a file upload XSS vulnerability in Generex CS141 below 2.06 version. The web application allows file uploading, making it possible to upload a file with HTML content. When HTML files are allowed, XSS payload can be injected into the uploaded file.

CVE-2022-47186 generex vulnerability CVSS: 0 28 Sep 2023, 14:15 UTC

There is an unrestricted upload of file vulnerability in Generex CS141 below 2.06 version. An attacker could upload and/or delete any type of file, without any format restriction and without any authentication, in the "upload" directory.

CVE-2022-47192 generex vulnerability CVSS: 0 31 Mar 2023, 22:15 UTC

Generex UPS CS141 below 2.06 version, could allow a remote attacker to upload a backup file containing a modified "users.json" to the web server of the device, allowing him to replace the administrator password.

CVE-2022-47191 generex vulnerability CVSS: 0 31 Mar 2023, 22:15 UTC

Generex UPS CS141 below 2.06 version, could allow a remote attacker to upload a firmware file containing a file with modified permissions, allowing him to escalate privileges.

CVE-2022-47190 generex vulnerability CVSS: 0 31 Mar 2023, 22:15 UTC

Generex UPS CS141 below 2.06 version, could allow a remote attacker to upload a firmware file containing a webshell that could allow him to execute arbitrary code as root.

CVE-2022-47189 generex vulnerability CVSS: 0 31 Mar 2023, 22:15 UTC

Generex UPS CS141 below 2.06 version, allows an attacker toupload a firmware file containing an incorrect configuration, in order to disrupt the normal functionality of the device.

CVE-2022-47188 generex vulnerability CVSS: 0 31 Mar 2023, 22:15 UTC

There is an arbitrary file reading vulnerability in Generex UPS CS141 below 2.06 version. An attacker, making use of the default credentials, could upload a backup file containing a symlink to /etc/shadow, allowing him to obtain the content of this path.

CVE-2022-42457 generex vulnerability CVSS: 0 06 Oct 2022, 18:18 UTC

Generex CS141 through 2.10 allows remote command execution by administrators via a web interface that reaches run_update in /usr/bin/gxserve-update.sh (e.g., command execution can occur via a reverse shell installed by install.sh).

CVE-2022-26041 generex vulnerability CVSS: 5.5 13 Jun 2022, 05:15 UTC

Directory traversal vulnerability in RCCMD 4.26 and earlier allows a remote authenticated attacker with an administrative privilege to read or alter an arbitrary file on the server via unspecified vectors.

CVE-2020-11420 generex vulnerability CVSS: 4.0 27 Apr 2020, 14:15 UTC

UPS Adapter CS141 before 1.90 allows Directory Traversal. An attacker with Admin or Engineer login credentials could exploit the vulnerability by manipulating variables that reference files and by doing this achieve access to files and directories outside the web root folder. An attacker may access arbitrary files and directories stored in the file system, but integrity of the files are not jeopardized as attacker have read access rights only.