2N records
9 published records for vendor 2n.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 55.6%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-117 Improper Output Neutralization for Logs1
- CWE-1286 Improper Validation of Syntactic Correctness of Input1
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')1
- CWE-295 Improper Certificate Validation1
- CWE-354 Improper Validation of Integrity Check Value1
- CWE-613 Insufficient Session Expiration1
The weakness classes this vendor ships most often: where to look.
CWEAll records
9 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
35Monitor | CVE-2025-59783No exploit | OS Command Injection over API2n · access commander · CWE-78 | High8.8 | — | 0.9% | Mar 4, 2026 |
31Monitor | CVE-2024-47255No exploit | In 2N Access Commander versions 3.1.1.2 and prior, a local attacker can escalate their privileges in the system which could allow for arbitr2n · access commander · CWE-354 | High7.8 | — | 0.1% | Nov 5, 2024 |
28Monitor | CVE-2024-47253No exploit | In 2N Access Commander versions 3.1.1.2 and prior, a Path Traversal vulnerability could allow an attacker with administrative privileges to 2n · access commander · CWE-22 | High7.2 | — | 1.0% | Nov 5, 2024 |
28Monitor | CVE-2024-47254No exploit | In 2N Access Commander versions 3.1.1.2 and prior, an Insufficient Verification of Data Authenticity vulnerability could allow an attacker 2n · access commander · CWE-807 | High7.2 | — | 0.4% | Nov 5, 2024 |
27Monitor | CVE-2025-59784No exploit | Log Pollution - Control Characters Not Escaped2n · access commander · CWE-117 | Medium6.9 | — | 0.3% | Mar 4, 2026 |
24Monitor | CVE-2025-59786No exploit | Cookies are not Invalidated upon Logout and Password Change2n · access commander · CWE-613 | Medium6.0 | — | 0.3% | Mar 4, 2026 |
23Monitor | CVE-2021-31399No exploit | On 2N Access Unit 2.0 2.31.0.40.5 devices, an attacker can pose as the web relay for a man-in-the-middle attack.2n · access unit 2.0 firmware · CWE-295 | Medium5.9 | — | 0.8% | Aug 13, 2021 |
21Monitor | CVE-2025-59787No exploit | HTTP 5XX Internal Server Errors2n · access commander · CWE-703 | Medium5.3 | — | 0.2% | Mar 4, 2026 |
21Monitor | CVE-2025-59785No exploit | API - Insufficient Input Validation2n · access commander · CWE-1286 | Medium5.3 | — | 0.2% | Mar 4, 2026 |
- CVE-2025-5978335Monitor
OS Command Injection over API
HighCVSS 8.8No exploitEPSS 1%2n · access commanderMar 4, 2026
- CVE-2024-4725531Monitor
In 2N Access Commander versions 3.1.1.2 and prior, a local attacker can escalate their privileges in the system which could allow for arbitr
HighCVSS 7.8No exploitEPSS 0%2n · access commanderNov 5, 2024
- CVE-2024-4725328Monitor
In 2N Access Commander versions 3.1.1.2 and prior, a Path Traversal vulnerability could allow an attacker with administrative privileges to
HighCVSS 7.2No exploitEPSS 1%2n · access commanderNov 5, 2024
- CVE-2024-4725428Monitor
In 2N Access Commander versions 3.1.1.2 and prior, an Insufficient Verification of Data Authenticity vulnerability could allow an attacker
HighCVSS 7.2No exploitEPSS 0%2n · access commanderNov 5, 2024
- CVE-2025-5978427Monitor
Log Pollution - Control Characters Not Escaped
MediumCVSS 6.9No exploitEPSS 0%2n · access commanderMar 4, 2026
- CVE-2025-5978624Monitor
Cookies are not Invalidated upon Logout and Password Change
MediumCVSS 6.0No exploitEPSS 0%2n · access commanderMar 4, 2026
- CVE-2021-3139923Monitor
On 2N Access Unit 2.0 2.31.0.40.5 devices, an attacker can pose as the web relay for a man-in-the-middle attack.
MediumCVSS 5.9No exploitEPSS 1%2n · access unit 2.0 firmwareAug 13, 2021
- CVE-2025-5978721Monitor
HTTP 5XX Internal Server Errors
MediumCVSS 5.3No exploitEPSS 0%2n · access commanderMar 4, 2026
- CVE-2025-5978521Monitor
API - Insufficient Input Validation
MediumCVSS 5.3No exploitEPSS 0%2n · access commanderMar 4, 2026