This page lists publicly disclosed CVE vulnerabilities affecting digi passport_firmware (linked via NVD CPE). Each row includes severity scores, summaries, and publication dates to help identify and analyze security issues.
| CVE | Summary | Source | Max CVSS | EPSS % | Published | Updated |
|---|---|---|---|---|---|---|
| CVE-2023-4299 | Digi RealPort Protocol is vulnerable to a replay attack that may allow an attacker to bypass authentication to access connected equipment. | [email protected] | 9.0 | 0.55% | 2023-08-31 | 2026-06-17 |
| CVE-2022-26953 | Digi Passport Firmware through 1.5.1,1 is affected by a buffer overflow. An attacker can supply a string in the page parameter for reboot.asp endpoint, allowing him to force an overflow when the string is concatenated to the HTML body. | [email protected] | 7.5 | 1.76% | 2022-04-05 | 2026-06-17 |
| CVE-2022-26952 | Digi Passport Firmware through 1.5.1,1 is affected by a buffer overflow in the function for building the Location header string when an unauthenticated user is redirected to the authentication page. | [email protected] | 7.5 | 1.98% | 2022-04-05 | 2026-06-17 |