avm records
9 published records for vendor avm.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 1 · 11.1%
- Pre-auth RCE
- 2
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor1
- CWE-310 Cryptographic Issues1
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')1
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')1
- CWE-94 Improper Control of Generation of Code ('Code Injection')1
The weakness classes this vendor ships most often: where to look.
CWEAll records
9 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
62This week | CVE-2014-9727Weaponized | AVM Fritz!Box allows remote attackers to execute arbitrary commands via shell metacharacters in the var:lang parameter to cgi-bin/webcm.avm · fritz\!box · CWE-78 | Critical10.0 | — | 71.7% | May 29, 2015 |
34Monitor | CVE-2014-8886No exploit | AVM FRITZ!OS before 6.30 extracts the contents of firmware updates before verifying their cryptographic signature, which allows remote attacavm · fritz\! os · CWE-310 | High8.1 | — | 6.1% | Jan 8, 2016 |
32Monitor | CVE-2007-0431No exploit | AVM Fritz!Box 7050, and possibly other product models, allows remote attackers to cause a denial of service (VoIP application crash) via a zavm · fritzbox | High7.8 | — | 2.4% | Jan 22, 2007 |
31Monitor | CVE-2014-8872No exploit | Improper Verification of Cryptographic Signature in AVM FRITZ!Box 6810 LTE after firmware 5.22, FRITZ!Box 6840 LTE after firmware 5.23, and avm · fritz\!box 6810 lte firmware · CWE-94 | High7.8 | — | 1.5% | Aug 28, 2017 |
31Monitor | CVE-2020-26887Proof of concept | FRITZ!OS before 7.21 on FRITZ!Box devices allows a bypass of a DNS Rebinding protection mechanism.avm · fritz\!box 7490 firmware | High7.8 | — | 1.4% | Oct 23, 2020 |
24Monitor | CVE-2015-7242No exploit | Cross-site scripting (XSS) vulnerability in the Push-Service-Mails feature in AVM FRITZ!OS before 6.30 allows remote attackers to inject arbavm · fritz\! os · CWE-79 | Medium6.1 | — | 1.5% | Jan 12, 2016 |
22Monitor | CVE-2000-0262Proof of concept | The AVM KEN! ISDN Proxy server allows remote attackers to cause a denial of service via a malformed request.avm · ken | Medium5.0 | — | 7.3% | Apr 12, 2000 |
20Monitor | CVE-2000-0261No exploit | The AVM KEN! web server allows remote attackers to read arbitrary files via a ..avm · ken | Medium5.0 | — | 1.6% | Apr 12, 2000 |
9Monitor | CVE-2017-8087No exploit | Information Leakage in PPPoE Packet Padding in AVM Fritz!Box 7490 with Firmware versions Fritz!OS 6.80 and 6.83 allows physically proximate avm · fritz\!os · CWE-200 | Low2.4 | — | 0.3% | Oct 22, 2019 |
- CVE-2014-972762This week
AVM Fritz!Box allows remote attackers to execute arbitrary commands via shell metacharacters in the var:lang parameter to cgi-bin/webcm.
CriticalCVSS 10.0WeaponizedEPSS 72%avm · fritz\!boxMay 29, 2015
- CVE-2014-888634Monitor
AVM FRITZ!OS before 6.30 extracts the contents of firmware updates before verifying their cryptographic signature, which allows remote attac
HighCVSS 8.1No exploitEPSS 6%avm · fritz\! osJan 8, 2016
- CVE-2007-043132Monitor
AVM Fritz!Box 7050, and possibly other product models, allows remote attackers to cause a denial of service (VoIP application crash) via a z
HighCVSS 7.8No exploitEPSS 2%avm · fritzboxJan 22, 2007
- CVE-2014-887231Monitor
Improper Verification of Cryptographic Signature in AVM FRITZ!Box 6810 LTE after firmware 5.22, FRITZ!Box 6840 LTE after firmware 5.23, and
HighCVSS 7.8No exploitEPSS 2%avm · fritz\!box 6810 lte firmwareAug 28, 2017
- CVE-2020-2688731Monitor
FRITZ!OS before 7.21 on FRITZ!Box devices allows a bypass of a DNS Rebinding protection mechanism.
HighCVSS 7.8Proof of conceptEPSS 1%avm · fritz\!box 7490 firmwareOct 23, 2020
- CVE-2015-724224Monitor
Cross-site scripting (XSS) vulnerability in the Push-Service-Mails feature in AVM FRITZ!OS before 6.30 allows remote attackers to inject arb
MediumCVSS 6.1No exploitEPSS 2%avm · fritz\! osJan 12, 2016
- CVE-2000-026222Monitor
The AVM KEN! ISDN Proxy server allows remote attackers to cause a denial of service via a malformed request.
MediumCVSS 5.0Proof of conceptEPSS 7%avm · kenApr 12, 2000
- CVE-2000-026120Monitor
The AVM KEN! web server allows remote attackers to read arbitrary files via a ..
MediumCVSS 5.0No exploitEPSS 2%avm · kenApr 12, 2000
- CVE-2017-80879Monitor
Information Leakage in PPPoE Packet Padding in AVM Fritz!Box 7490 with Firmware versions Fritz!OS 6.80 and 6.83 allows physically proximate
LowCVSS 2.4No exploitEPSS 0%avm · fritz\!osOct 22, 2019