VYPR
Vendor

Xinje

Products
7
CVEs
8
Across products
13
Status
Private

Products

7

Recent CVEs

8
  • CVE-2023-5463HigOct 9, 2023
    risk 0.51cvss 7.8epss 0.00

    A vulnerability was found in XINJE XDPPro up to 3.7.17a. It has been rated as critical. Affected by this issue is some unknown functionality in the library cfgmgr32.dll. The manipulation leads to uncontrolled search path. An attack has to be approached locally. The exploit has…

  • CVE-2024-50954HigJan 15, 2025
    risk 0.49cvss 7.5epss 0.00

    The XINJE XL5E-16T and XD5E-24R-E programmable logic controllers V3.5.3b-V3.7.2a have a vulnerability in handling Modbus messages. When a TCP connection is established with the above series of controllers within a local area network (LAN), sending a specific Modbus message to…

  • CVE-2024-50953HigJan 15, 2025
    risk 0.49cvss 7.5epss 0.00

    An issue in XINJE XL5E-16T V3.7.2a allows attackers to cause a Denial of Service (DoS) via a crafted Modbus message.

  • CVE-2024-50955HigNov 13, 2024
    risk 0.49cvss 7.5epss 0.00

    An issue in how XINJE XD5E-24R and XL5E-16T v3.5.3b handles TCP protocol messages allows attackers to cause a Denial of Service (DoS) via a crafted TCP message.

  • CVE-2021-34605HigMay 11, 2022
    risk 0.48cvss 7.3epss 0.02

    A zip slip vulnerability in XINJE XD/E Series PLC Program Tool up to version v3.5.1 can provide an attacker with arbitrary file write privilege when opening a specially-crafted project file. This vulnerability can be triggered by manually opening an infected project file, or by…

  • CVE-2021-34606HigMay 11, 2022
    risk 0.47cvss 7.3epss 0.00

    A vulnerability exists in XINJE XD/E Series PLC Program Tool in versions up to v3.5.1 that can allow an authenticated, local attacker to load a malicious DLL. Local access is required to successfully exploit this vulnerability. This means the potential attacker must have access…

  • CVE-2023-5462MedOct 9, 2023
    risk 0.42cvss 6.5epss 0.01

    A vulnerability was found in XINJE XD5E-30R-E 3.5.3b. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the component Modbus Handler. The manipulation leads to denial of service. The exploit has been disclosed to the public and may…

  • CVE-2024-52783MedJan 15, 2025
    risk 0.33cvss 5.1epss 0.00

    Insecure permissions in the XNetSocketClient component of XINJE XDPPro.exe v3.2.2 to v3.7.17c allows attackers to execute arbitrary code via modification of the configuration file.