Security Advisories

We keep this list of security information for the products icom Connectivity Suite, icom Router Management and all routers with the operating system icom OS up to date.

Subscribe to security alerts

Receive all security-related information about our products. Register now for our security newsletter. We will notify you by email as soon as new security advisories are published.

Learn more

Would you like to learn more about IT security at INSYS icom? You can find more information on the topic here

Report a vulnerability

You would like to inform us about a security note or have questions about IT security at INSYS icom? Please send an e-mail to security@insys-icom.com or use our secure online form.

TitleSeverity levelCVE IDProducts concernedRelease dateDownloadSolution
Multiple Linux Kernel vulnerabilitiesHighCVE-2026-31668, CVE-2026-43038, CVE-2026-43284, CVE-2026-43037, CVE-2026-31685, CVE-2026-31682, CVE-2026-43500icomOS <= 9.42026-05-12PDF versionicomOS 9.5
Copy Fail / Linux Kernel Local Privilege EscalationInformationalCVE-2026-31431No products affected2026-05-06PDF version-
Stack buffer overflow in CMS AuthEnvelopedData parsingHighCVE-2025-15467icom OS >= 9.02026-02-06PDF versionicomOS 9.4
Multiple CVEs in OpenSSL libraryLowCVE-2025-11187, CVE-2025-69421, CVE-2026-22795, CVE-2026-22796, CVE-2025-15468, CVE-2025-15469, CVE-2025-66199, CVE-2025-68160, CVE-2025-69418, CVE-2025-69419, CVE-2025-69420icom OS >= 9.02026-02-06PDF versionicomOS 9.4
Multiple Vulnerabilities in OpenSSL
library
LowCVE-2025-15467, CVE-2025-15468, CVE-2025-15469, CVE-2025-66199, CVE-2025-69419, CVE-2025-69420 , CVE-2025-69421 , CVE-2026-22795, CVE-2026-22796icom Connectivity Suite (iCS)2026-02-06PDF version
Multiple Vulnerabilities in OpenSSL
library
Not affectedCVE-2025-15467, CVE-2025-15468, CVE-2025-15469, CVE-2025-66199, CVE-2025-69419, CVE-2025-69420 , CVE-2025-69421 , CVE-2026-22795, CVE-2026-22796icom Router Management (iRM)2026-02-06Not affected
Improper validation of source IP addresses in OpenVPNHighCVE-2025-13086icom OS >= 7.02026-02-06PDF versionicomOS 9.4
Improper validation of source IP addresses in OpenVPNNot affectedCVE-2025-13086icom Connectivity Suite (iCS), icom Router Management (iRM)2026-02-06Not affected
Privilege Escalation Vulnerability in Dropbear SSH ServerHighCVE-2025-14282No product affected2025-12-16PDF version
React Server Remote Code Execution Vulnerability (React2Shell)CriticalCVE-2025-55182No product affected2025-12-15PDF version
Status User role exceeds intended permissionsMediumicom OS 8.82025-06-14PDF versionicom OS 8.9
CVE-2024-50302 – Linux Kernel VulnerabilityLowCVE-2024-50302icom OS2025-03-06PDF versionicom OS 8.5
Low-Risk Vulnerability in Router Configuration when Firewall allows all Incoming TrafficLow (no CVE score available)icom OS2025-02-26PDF versionicom OS 8.8
Missing 2FA Validation on New UI EndpointsHigh (CVSS v3 Base Score: 8.1)icom Connectivity Suite2025-01-16PDF versionfixed
Input Validation Flaw in icomOS Firewall and Port Rules HandlingMediumAll icom OS versions2024-11-27PDF versionSolution: icom OS 8.4
OpenVPNCriticalCVE-2023-46850icom OS 7.0 - 7.92024-10-10PDF versionicom OS 8.0
OpenVPNHighCVE-2023-46849
icom OS 7.0 - 7.92024-10-10PDF versionicom OS 8.0
OpenSSHInformationalCVE-2024-6387
none2024-07-17PDF version
XZ Utils BackdoorInformationalCVE-2024-3094
none2024-04-08PDF version
OpenSSH
Terrapin Attack
MediumCVE-2023-48795
icom OS 5.2 or higher2024-01-11PDF versionicom OS V7.9
Open tcp port 8888informationalicom OS 5.5 or higher2023-03-20PDF versionicom OS V6.10
OpenSSL 3.0informationalCVE-2022-3602
CVE-2022-3786
none2022-11-02PDF version
Log4jinformationalCVE-2021-44228none2021-12-13PDF version
Multiple
vulnerabilities
in cURL and
openSSL
HighcURL
CVE-2020-8286
CVE-2020-8285
CVE-2020-8284
CVE-2020-8231
CVE-2020-8177
CVE-2020-8169

openSSL
CVE-2020-1967
CVE-2020-1971

icom OS 4.4
or lower
2021-02-03PDF versionicom OS V4.5
dnsmasq
multiple
vulnerabilities
HighCVE-2020-25681
CVE-2020-25682
CVE-2020-25683
CVE-2020-25684
CVE-2020-25685
CVE-2020-25686
CVE-2020-25687
CVE-2020-25687
icom OS 4.4
or lower
2021-02-02PDF versionicom OS V4.5
Amnesia:33Informationalnone2020-09-28PDF version
Ripple20Informationalnone2020-06-24PDF version
pppd
buffer
overflow
CriticalCVE-2020-8597icom OS 4.1
or lower
2020-05-30PDF versionicom OS V4.2
or greater

Contact form for security notes

You would like to inform us about a security note or have questions about IT security at INSYS icom?
Please use our secure online form.