Ericsson records
45 published records for vendor ericsson.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 51.1%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')9
- CWE-228 Improper Handling of Syntactically Invalid Structure3
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')3
- CWE-601 URL Redirection to Untrusted Site ('Open Redirect')2
- CWE-230 Improper Handling of Missing Values2
- CWE-20 Improper Input Validation2
The weakness classes this vendor ships most often: where to look.
CWEAll records
45 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
52Plan | CVE-2024-10081Proof of concept | CodeChecker is an analyzer tooling, defect database and viewer extension for the Clang Static Analyzer and Clang Tidy.ericsson · codechecker · CWE-288 | Critical10.0 | — | 39.9% | Nov 6, 2024 |
38Monitor | CVE-2021-43339Proof of concept | In Ericsson Network Location before 2021-07-31, it is possible for an authenticated attacker to inject commands via file_name in the export ericsson · network location · CWE-77 | High8.8 | — | 9.6% | Nov 3, 2021 |
37Monitor | CVE-2026-25660No exploit | Authentication bypass for certain API callsericsson · codechecker · CWE-290 | Critical9.3 | — | 0.6% | Apr 24, 2026 |
36Monitor | CVE-2024-10082No exploit | CodeChecker is an analyzer tooling, defect database and viewer extension for the Clang Static Analyzer and Clang Tidy.ericsson · codechecker · CWE-305 | Critical9.0 | — | 0.5% | Nov 6, 2024 |
35Monitor | CVE-2022-47531No exploit | An issue was discovered in Ericsson Evolved Packet Gateway (EPG) versions 3.x before 3.25 and 2.x before 2.16, allows authenticated users toericsson · evolved packet gateway | High8.8 | — | 1.0% | Dec 5, 2023 |
35Monitor | CVE-2023-39909No exploit | Ericsson Network Manager before 23.2 mishandles Access Control and thus unauthenticated low-privilege users can access the NCM application.ericsson · network manager | High8.8 | — | 0.8% | Dec 7, 2023 |
34Monitor | CVE-2025-27262No exploit | Ericsson Indoor Connect 8855 - Improper Neutralization of Special Elements used in an OS Command Vulnerabilityericsson · indoor connect 8855 firmware · CWE-78 | High8.5 | — | 0.7% | Sep 25, 2025 |
34Monitor | CVE-2025-40836No exploit | Ericsson Indoor Connect 8855 - Improper Input Validation Vulnerabilityericsson · indoor connect 8855 firmware · CWE-20 | High8.7 | — | 0.4% | Sep 25, 2025 |
34Monitor | CVE-2025-27261No exploit | Ericsson Indoor Connect 8855 - Improper Neutralization of Special Elements used in an SQL Command Vulnerabilityericsson · indoor connect 8855 firmware · CWE-89 | High8.7 | — | 0.3% | Sep 25, 2025 |
34Monitor | CVE-2025-40837No exploit | Ericsson Indoor Connect 8855 - Missing Authorization Vulnerabilityericsson · indoor connect 8855 firmware · CWE-862 | High8.7 | — | 0.3% | Sep 25, 2025 |
34Monitor | CVE-2025-40842No exploit | Ericsson Indoor Connect 8855 - Improper Neutralization of Input During Web Page Generation Vulnerabilityericsson · indoor connect 8855 firmware · CWE-79 | High8.5 | — | 0.1% | Mar 25, 2026 |
32Monitor | CVE-2021-41390No exploit | In Ericsson ECM before 18.0, it was observed that Security Provider Endpoint in the User Profile Management Section is vulnerable to CSV Injericsson · enterprise content management · CWE-74 | High8.0 | — | 1.1% | Sep 17, 2021 |
32Monitor | CVE-2024-53829No exploit | Cross-Site Request Forgery in CodeChecker APIericsson · codechecker · CWE-352 | High8.2 | — | 0.3% | Jan 21, 2025 |
31Monitor | CVE-2003-1442Proof of concept | The web administration page for the Ericsson HM220dp ADSL modem does not require authentication, which could allow remote attackers to gain ericsson · hm220dp adsl modem · CWE-287 | High7.5 | — | 2.6% | Dec 31, 2003 |
31Monitor | CVE-2025-40843No exploit | Buffer overflow in CodeChecker log commandericsson · codechecker · CWE-121 | High7.8 | — | 0.2% | Oct 28, 2025 |
28Monitor | CVE-2015-2166Proof of concept | Directory traversal vulnerability in the Instance Monitor in Ericsson Drutt Mobile Service Delivery Platform (MSDP) 4, 5, and 6 allows remotericsson · drutt mobile service delivery platform · CWE-22 | Medium5.0 | — | 26.8% | Apr 6, 2015 |
28Monitor | CVE-2024-25007No exploit | Ericsson Network Manager - Improper Neutralization of Formula Elements Vulnerabilityericsson · network manager · CWE-1236 | High7.1 | — | 0.4% | Apr 4, 2024 |
28Monitor | CVE-2026-25658No exploit | Ericsson Packet Core Gateway (PCG) - Improper handling of missing values Vulnerabilityericsson · packet core gateway · CWE-230 | High7.1 | — | 0.3% | Jun 5, 2026 |
28Monitor | CVE-2026-25659No exploit | Ericsson Packet Core Gateway (PCG) - Improper handling of missing values Vulnerabilityericsson · packet core gateway · CWE-230 | High7.1 | — | 0.3% | Jun 5, 2026 |
28Monitor | CVE-2026-25657No exploit | Ericsson Packet Core Gateway (PCG) - Improper Handling of Syntactically Invalid Structure Vulnerabilityericsson · packet core gateway · CWE-228 | High7.1 | — | 0.3% | Jun 5, 2026 |
28Monitor | CVE-2025-27260No exploit | Ericsson Indoor Connect 8855 - Improper Filtering of Special Elements Vulnerabilityericsson · indoor connect 8855 firmware · CWE-790 | High7.2 | — | 0.2% | Mar 25, 2026 |
28Monitor | CVE-2025-59174No exploit | Ericsson Packet Core Controller (PCC) versions prior to 1.39 contain a vulnerability where an attacker sending a large volume of specially cericsson · packet core controller · CWE-228 | High7.1 | — | 0.2% | Jun 5, 2026 |
27Monitor | CVE-2022-46408No exploit | Ericsson Network Manager (ENM), versions prior to 22.1, contains a vulnerability in the application Network Connectivity Manager (NCM) whereericsson · network manager · CWE-1236 | Medium6.8 | — | 0.9% | Jun 28, 2023 |
27Monitor | CVE-2025-27258No exploit | Ericsson Network Manager: escalation of privilege vulnerabilityericsson · network manager · CWE-284 | Medium6.9 | — | 0.3% | Oct 13, 2025 |
27Monitor | CVE-2024-25008No exploit | Ericsson RAN Compute and Site Controller 6610 - Improper Input Validation Vulnerabilityericsson · ericsson ran compute basebands (all bb variants) · CWE-20 | Medium6.8 | — | 0.3% | Aug 16, 2024 |
- CVE-2024-1008152Plan
CodeChecker is an analyzer tooling, defect database and viewer extension for the Clang Static Analyzer and Clang Tidy.
CriticalCVSS 10.0Proof of conceptEPSS 40%ericsson · codecheckerNov 6, 2024
- CVE-2021-4333938Monitor
In Ericsson Network Location before 2021-07-31, it is possible for an authenticated attacker to inject commands via file_name in the export
HighCVSS 8.8Proof of conceptEPSS 10%ericsson · network locationNov 3, 2021
- CVE-2026-2566037Monitor
Authentication bypass for certain API calls
CriticalCVSS 9.3No exploitEPSS 1%ericsson · codecheckerApr 24, 2026
- CVE-2024-1008236Monitor
CodeChecker is an analyzer tooling, defect database and viewer extension for the Clang Static Analyzer and Clang Tidy.
CriticalCVSS 9.0No exploitEPSS 0%ericsson · codecheckerNov 6, 2024
- CVE-2022-4753135Monitor
An issue was discovered in Ericsson Evolved Packet Gateway (EPG) versions 3.x before 3.25 and 2.x before 2.16, allows authenticated users to
HighCVSS 8.8No exploitEPSS 1%ericsson · evolved packet gatewayDec 5, 2023
- CVE-2023-3990935Monitor
Ericsson Network Manager before 23.2 mishandles Access Control and thus unauthenticated low-privilege users can access the NCM application.
HighCVSS 8.8No exploitEPSS 1%ericsson · network managerDec 7, 2023
- CVE-2025-2726234Monitor
Ericsson Indoor Connect 8855 - Improper Neutralization of Special Elements used in an OS Command Vulnerability
HighCVSS 8.5No exploitEPSS 1%ericsson · indoor connect 8855 firmwareSep 25, 2025
- CVE-2025-4083634Monitor
Ericsson Indoor Connect 8855 - Improper Input Validation Vulnerability
HighCVSS 8.7No exploitEPSS 0%ericsson · indoor connect 8855 firmwareSep 25, 2025
- CVE-2025-2726134Monitor
Ericsson Indoor Connect 8855 - Improper Neutralization of Special Elements used in an SQL Command Vulnerability
HighCVSS 8.7No exploitEPSS 0%ericsson · indoor connect 8855 firmwareSep 25, 2025
- CVE-2025-4083734Monitor
Ericsson Indoor Connect 8855 - Missing Authorization Vulnerability
HighCVSS 8.7No exploitEPSS 0%ericsson · indoor connect 8855 firmwareSep 25, 2025
- CVE-2025-4084234Monitor
Ericsson Indoor Connect 8855 - Improper Neutralization of Input During Web Page Generation Vulnerability
HighCVSS 8.5No exploitEPSS 0%ericsson · indoor connect 8855 firmwareMar 25, 2026
- CVE-2021-4139032Monitor
In Ericsson ECM before 18.0, it was observed that Security Provider Endpoint in the User Profile Management Section is vulnerable to CSV Inj
HighCVSS 8.0No exploitEPSS 1%ericsson · enterprise content managementSep 17, 2021
- CVE-2024-5382932Monitor
Cross-Site Request Forgery in CodeChecker API
HighCVSS 8.2No exploitEPSS 0%ericsson · codecheckerJan 21, 2025
- CVE-2003-144231Monitor
The web administration page for the Ericsson HM220dp ADSL modem does not require authentication, which could allow remote attackers to gain
HighCVSS 7.5Proof of conceptEPSS 3%ericsson · hm220dp adsl modemDec 31, 2003
- CVE-2025-4084331Monitor
Buffer overflow in CodeChecker log command
HighCVSS 7.8No exploitEPSS 0%ericsson · codecheckerOct 28, 2025
- CVE-2015-216628Monitor
Directory traversal vulnerability in the Instance Monitor in Ericsson Drutt Mobile Service Delivery Platform (MSDP) 4, 5, and 6 allows remot
MediumCVSS 5.0Proof of conceptEPSS 27%ericsson · drutt mobile service delivery platformApr 6, 2015
- CVE-2024-2500728Monitor
Ericsson Network Manager - Improper Neutralization of Formula Elements Vulnerability
HighCVSS 7.1No exploitEPSS 0%ericsson · network managerApr 4, 2024
- CVE-2026-2565828Monitor
Ericsson Packet Core Gateway (PCG) - Improper handling of missing values Vulnerability
HighCVSS 7.1No exploitEPSS 0%ericsson · packet core gatewayJun 5, 2026
- CVE-2026-2565928Monitor
Ericsson Packet Core Gateway (PCG) - Improper handling of missing values Vulnerability
HighCVSS 7.1No exploitEPSS 0%ericsson · packet core gatewayJun 5, 2026
- CVE-2026-2565728Monitor
Ericsson Packet Core Gateway (PCG) - Improper Handling of Syntactically Invalid Structure Vulnerability
HighCVSS 7.1No exploitEPSS 0%ericsson · packet core gatewayJun 5, 2026
- CVE-2025-2726028Monitor
Ericsson Indoor Connect 8855 - Improper Filtering of Special Elements Vulnerability
HighCVSS 7.2No exploitEPSS 0%ericsson · indoor connect 8855 firmwareMar 25, 2026
- CVE-2025-5917428Monitor
Ericsson Packet Core Controller (PCC) versions prior to 1.39 contain a vulnerability where an attacker sending a large volume of specially c
HighCVSS 7.1No exploitEPSS 0%ericsson · packet core controllerJun 5, 2026
- CVE-2022-4640827Monitor
Ericsson Network Manager (ENM), versions prior to 22.1, contains a vulnerability in the application Network Connectivity Manager (NCM) where
MediumCVSS 6.8No exploitEPSS 1%ericsson · network managerJun 28, 2023
- CVE-2025-2725827Monitor
Ericsson Network Manager: escalation of privilege vulnerability
MediumCVSS 6.9No exploitEPSS 0%ericsson · network managerOct 13, 2025
- CVE-2024-2500827Monitor
Ericsson RAN Compute and Site Controller 6610 - Improper Input Validation Vulnerability
MediumCVSS 6.8No exploitEPSS 0%ericsson · ericsson ran compute basebands (all bb variants)Aug 16, 2024