nedi CVE Vulnerabilities & Metrics

Focus on nedi vulnerabilities and metrics.

Last updated: 08 Mar 2025, 23:25 UTC

About nedi Security Exposure

This page consolidates all known Common Vulnerabilities and Exposures (CVEs) associated with nedi. We track both calendar-based metrics (using fixed periods) and rolling metrics (using gliding windows) to give you a comprehensive view of security trends and risk evolution. Use these insights to assess risk and plan your patching strategy.

For a broader perspective on cybersecurity threats, explore the comprehensive list of CVEs by vendor and product. Stay updated on critical vulnerabilities affecting major software and hardware providers.

Global CVE Overview

Total nedi CVEs: 26
Earliest CVE date: 17 Jan 2019, 02:29 UTC
Latest CVE date: 06 Oct 2022, 18:16 UTC

Latest CVE reference: CVE-2022-40895

Rolling Stats

30-day Count (Rolling): 0
365-day Count (Rolling): 0

Calendar-based Variation

Calendar-based Variation compares a fixed calendar period (e.g., this month versus the same month last year), while Rolling Growth Rate uses a continuous window (e.g., last 30 days versus the previous 30 days) to capture trends independent of calendar boundaries.

Variations & Growth

Month Variation (Calendar): 0%
Year Variation (Calendar): 0%

Month Growth Rate (30-day Rolling): 0.0%
Year Growth Rate (365-day Rolling): 0.0%

Monthly CVE Trends (current vs previous Year)

Annual CVE Trends (Last 20 Years)

Critical nedi CVEs (CVSS ≥ 9) Over 20 Years

CVSS Stats

Average CVSS: 4.49

Max CVSS: 9.0

Critical CVEs (≥9): 2

CVSS Range vs. Count

Range Count
0.0-3.9 13
4.0-6.9 11
7.0-8.9 0
9.0-10.0 2

CVSS Distribution Chart

Top 5 Highest CVSS nedi CVEs

These are the five CVEs with the highest CVSS scores for nedi, sorted by severity first and recency.

All CVEs for nedi

CVE-2022-40895 nedi vulnerability CVSS: 0 06 Oct 2022, 18:16 UTC

In certain Nedi products, a vulnerability in the web UI of NeDi login & Community login could allow an unauthenticated, remote attacker to affect the integrity of a device via a User Enumeration vulnerability. The vulnerability is due to insecure design, where a difference in forgot password utility could allow an attacker to determine if the user is valid or not, enabling a brute force attack with valid users. This affects NeDi 1.0.7 for OS X 1.0.7 <= and NeDi for Suse 1.0.7 <= and NeDi for FreeBSD 1.0.7 <=.

CVE-2021-26753 nedi vulnerability CVSS: 6.5 12 Feb 2021, 21:15 UTC

NeDi 1.9C allows an authenticated user to inject PHP code in the System Files function on the endpoint /System-Files.php via the txt HTTP POST parameter. This allows an attacker to obtain access to the operating system where NeDi is installed and to all application data.

CVE-2021-26752 nedi vulnerability CVSS: 6.5 12 Feb 2021, 21:15 UTC

NeDi 1.9C allows an authenticated user to execute operating system commands in the Nodes Traffic function on the endpoint /Nodes-Traffic.php via the md or ag HTTP GET parameter. This allows an attacker to obtain access to the operating system where NeDi is installed and to all application data.

CVE-2021-26751 nedi vulnerability CVSS: 4.0 12 Feb 2021, 21:15 UTC

NeDi 1.9C allows an authenticated user to perform a SQL Injection in the Monitoring History function on the endpoint /Monitoring-History.php via the det HTTP GET parameter. This allows an attacker to access all the data in the database and obtain access to the NeDi application.

CVE-2020-23989 nedi vulnerability CVSS: 3.5 02 Nov 2020, 22:15 UTC

NeDi 1.9C allows pwsec.php oid XSS.

CVE-2020-23868 nedi vulnerability CVSS: 3.5 02 Nov 2020, 22:15 UTC

NeDi 1.9C allows inc/rt-popup.php d XSS.

CVE-2020-15035 nedi vulnerability CVSS: 3.5 07 Jul 2020, 16:15 UTC

NeDi 1.9C is vulnerable to cross-site scripting (XSS) attack. The application allows an attacker to execute arbitrary JavaScript code via the Monitoring-Map.php hde parameter.

CVE-2020-15034 nedi vulnerability CVSS: 3.5 07 Jul 2020, 16:15 UTC

NeDi 1.9C is vulnerable to cross-site scripting (XSS) attack. The application allows an attacker to execute arbitrary JavaScript code via the Monitoring-Setup.php tet parameter.

CVE-2020-15033 nedi vulnerability CVSS: 3.5 07 Jul 2020, 16:15 UTC

NeDi 1.9C is vulnerable to cross-site scripting (XSS) attack. The application allows an attacker to execute arbitrary JavaScript code via the snmpget.php ip parameter.

CVE-2020-15032 nedi vulnerability CVSS: 3.5 07 Jul 2020, 16:15 UTC

NeDi 1.9C is vulnerable to cross-site scripting (XSS) attack. The application allows an attacker to execute arbitrary JavaScript code via the Monitoring-Incidents.php id parameter.

CVE-2020-15031 nedi vulnerability CVSS: 3.5 07 Jul 2020, 16:15 UTC

NeDi 1.9C is vulnerable to cross-site scripting (XSS) attack. The application allows an attacker to execute arbitrary JavaScript code via the Assets-Management.php chg parameter.

CVE-2020-15030 nedi vulnerability CVSS: 3.5 07 Jul 2020, 16:15 UTC

NeDi 1.9C is vulnerable to cross-site scripting (XSS) attack. The application allows an attacker to execute arbitrary JavaScript code via the Topology-Routes.php rtr parameter.

CVE-2020-15029 nedi vulnerability CVSS: 3.5 07 Jul 2020, 16:15 UTC

NeDi 1.9C is vulnerable to cross-site scripting (XSS) attack. The application allows an attacker to execute arbitrary JavaScript code via the Assets-Management.php sn parameter.

CVE-2020-15028 nedi vulnerability CVSS: 3.5 07 Jul 2020, 16:15 UTC

NeDi 1.9C is vulnerable to a cross-site scripting (XSS) attack. The application allows an attacker to execute arbitrary JavaScript code via the Topology-Map.php xo parameter.

CVE-2020-15037 nedi vulnerability CVSS: 3.5 07 Jul 2020, 15:15 UTC

NeDi 1.9C is vulnerable to cross-site scripting (XSS) attack. The application allows an attacker to execute arbitrary JavaScript code via the Reports-Devices.php page st[] parameter.

CVE-2020-15036 nedi vulnerability CVSS: 3.5 07 Jul 2020, 15:15 UTC

NeDi 1.9C is vulnerable to cross-site scripting (XSS) attack. The application allows an attacker to execute arbitrary JavaScript code via the Topology-Linked.php dv parameter.

CVE-2020-14414 nedi vulnerability CVSS: 9.0 29 Jun 2020, 17:15 UTC

NeDi 1.9C is vulnerable to Remote Command Execution. pwsec.php improperly escapes shell metacharacters from a POST request. An attacker can exploit this by crafting an arbitrary payload (any system commands) that contains shell metacharacters via a POST request with a pw parameter. (This can also be exploited via CSRF.)

CVE-2020-14413 nedi vulnerability CVSS: 4.3 29 Jun 2020, 17:15 UTC

NeDi 1.9C is vulnerable to XSS because of an incorrect implementation of sanitize() in inc/libmisc.php. This function attempts to escape the SCRIPT tag from user-controllable values, but can be easily bypassed, as demonstrated by an onerror attribute of an IMG element as a Devices-Config.php?sta= value.

CVE-2020-14412 nedi vulnerability CVSS: 9.0 29 Jun 2020, 17:15 UTC

NeDi 1.9C is vulnerable to Remote Command Execution. System-Snapshot.php improperly escapes shell metacharacters from a POST request. An attacker can exploit this by crafting an arbitrary payload (any system commands) that contains shell metacharacters via a POST request with a psw parameter. (This can also be exploited via CSRF.)

CVE-2020-15017 nedi vulnerability CVSS: 4.3 26 Jun 2020, 14:15 UTC

NeDi 1.9C is vulnerable to reflected cross-site scripting. The Devices-Config.php file improperly validates user input. An attacker can exploit this vulnerability by crafting arbitrary JavaScript in the sta GET parameter.

CVE-2020-15016 nedi vulnerability CVSS: 4.3 26 Jun 2020, 14:15 UTC

NeDi 1.9C is vulnerable to reflected cross-site scripting. The Other-Converter.php file improperly validates user input. An attacker can exploit this vulnerability by crafting arbitrary JavaScript in the txt GET parameter.

CVE-2018-20731 nedi vulnerability CVSS: 4.3 17 Jan 2019, 02:29 UTC

A stored cross site scripting (XSS) vulnerability in NeDi before 1.7Cp3 allows remote attackers to inject arbitrary web script or HTML via User-Chat.php.

CVE-2018-20730 nedi vulnerability CVSS: 5.0 17 Jan 2019, 02:29 UTC

A SQL injection vulnerability in NeDi before 1.7Cp3 allows any user to execute arbitrary SQL read commands via the query.php component.

CVE-2018-20729 nedi vulnerability CVSS: 4.3 17 Jan 2019, 02:29 UTC

A reflected cross site scripting (XSS) vulnerability in NeDi before 1.7Cp3 allows remote attackers to inject arbitrary web script or HTML via the reg parameter in mh.php.

CVE-2018-20728 nedi vulnerability CVSS: 6.8 17 Jan 2019, 02:29 UTC

A cross site request forgery (CSRF) vulnerability in NeDi before 1.7Cp3 allows remote attackers to escalate privileges via User-Management.php.

CVE-2018-20727 nedi vulnerability CVSS: 6.5 17 Jan 2019, 02:29 UTC

Multiple command injection vulnerabilities in NeDi before 1.7Cp3 allow authenticated users to execute code on the server side via the flt parameter to Nodes-Traffic.php, the dv parameter to Devices-Graph.php, or the tit parameter to drawmap.php.