Actiontec records
14 published records for vendor actiontec.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 5
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-120 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')2
- CWE-121 Stack-based Buffer Overflow2
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')2
- CWE-269 Improper Privilege Management1
- CWE-287 Improper Authentication1
- CWE-352 Cross-Site Request Forgery (CSRF)1
The weakness classes this vendor ships most often: where to look.
CWEAll records
14 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
40Plan | CVE-2018-15556No exploit | The Quantenna WiFi Controller on Telus Actiontec WEB6000Q v1.1.02.22 allows login with root level access with the user "root" and an empty pactiontec · web6000q firmware · CWE-287 | Critical9.8 | — | 3.3% | Jun 27, 2019 |
40Plan | CVE-2018-15555No exploit | On Telus Actiontec WEB6000Q v1.1.02.22 devices, an attacker can login with root level access with the user "root" and password "admin" by usactiontec · web6000q firmware · CWE-662 | Critical9.8 | — | 3.0% | Jun 28, 2019 |
36Monitor | CVE-2018-15557No exploit | An issue was discovered in the Quantenna WiFi Controller on Telus Actiontec WEB6000Q v1.1.02.22 devices.actiontec · web6000q firmware · CWE-269 | High8.8 | — | 3.3% | Jun 27, 2019 |
35Monitor | CVE-2024-6145No exploit | Actiontec WCB6200Q Cookie Format String Remote Code Execution Vulnerabilityactiontec · wcb6200q firmware · CWE-134 | High8.8 | — | 1.2% | Jun 18, 2024 |
35Monitor | CVE-2024-6142No exploit | Actiontec WCB6200Q uh_tcp_recv_content Buffer Overflow Remote Code Execution Vulnerabilityactiontec · wcb6200q firmware · CWE-120 | High8.8 | — | 1.1% | Jun 18, 2024 |
35Monitor | CVE-2024-6144No exploit | Actiontec WCB6200Q Multipart Boundary Stack-based Buffer Overflow Remote Code Execution Vulnerabilityactiontec · wcb6200q firmware · CWE-121 | High8.8 | — | 1.1% | Jun 18, 2024 |
35Monitor | CVE-2024-6146No exploit | Actiontec WCB6200Q uh_get_postdata_withupload Stack-based Buffer Overflow Remote Code Execution Vulnerabilityactiontec · wcb6200q firmware · CWE-121 | High8.8 | — | 1.1% | Jun 18, 2024 |
35Monitor | CVE-2024-6143No exploit | Actiontec WCB6200Q uh_tcp_recv_header Buffer Overflow Remote Code Execution Vulnerabilityactiontec · wcb6200q firmware · CWE-120 | High8.8 | — | 1.1% | Jun 18, 2024 |
33Monitor | CVE-2015-2904No exploit | Actiontec GT784WN modems with firmware before NCS01-1.0.13 have hardcoded credentials, which makes it easier for remote attackers to obtain actiontec · ncs01 firmware | High8.3 | — | 0.9% | Aug 23, 2015 |
32Monitor | CVE-2018-10252No exploit | An issue was discovered on Actiontec WCB6200Q before 1.1.10.20a devices.actiontec · wcb6200q firmware · CWE-384 | High8.1 | — | 0.9% | May 14, 2018 |
27Monitor | CVE-2015-2905No exploit | Cross-site request forgery (CSRF) vulnerability on Actiontec GT784WN modems with firmware before NCS01-1.0.13 allows remote attackers to hijactiontec · ncs01 firmware · CWE-352 | Medium6.8 | — | 0.7% | Aug 23, 2015 |
27Monitor | CVE-2019-12789No exploit | An issue was discovered on Actiontec T2200H T2200H-31.128L.08 devices, as distributed by Telus.actiontec · t2200h firmware | Medium6.8 | — | 0.6% | Jun 17, 2019 |
24Monitor | CVE-2013-3097No exploit | Unspecified Cross-site scripting (XSS) vulnerability in the Verizon FIOS Actiontec MI424WR-GEN3I router.actiontec · mi424wr-gen3i firmware · CWE-79 | Medium6.1 | — | 1.5% | Nov 13, 2019 |
24Monitor | CVE-2018-19922No exploit | Persistent Cross-Site Scripting (XSS) in the advancedsetup_websiteblocking.html Website Blocking page of the Actiontec C1000A router with fiactiontec · c1000a firmware · CWE-79 | Medium6.1 | — | 0.8% | Dec 6, 2018 |
- CVE-2018-1555640Plan
The Quantenna WiFi Controller on Telus Actiontec WEB6000Q v1.1.02.22 allows login with root level access with the user "root" and an empty p
CriticalCVSS 9.8No exploitEPSS 3%actiontec · web6000q firmwareJun 27, 2019
- CVE-2018-1555540Plan
On Telus Actiontec WEB6000Q v1.1.02.22 devices, an attacker can login with root level access with the user "root" and password "admin" by us
CriticalCVSS 9.8No exploitEPSS 3%actiontec · web6000q firmwareJun 28, 2019
- CVE-2018-1555736Monitor
An issue was discovered in the Quantenna WiFi Controller on Telus Actiontec WEB6000Q v1.1.02.22 devices.
HighCVSS 8.8No exploitEPSS 3%actiontec · web6000q firmwareJun 27, 2019
- CVE-2024-614535Monitor
Actiontec WCB6200Q Cookie Format String Remote Code Execution Vulnerability
HighCVSS 8.8No exploitEPSS 1%actiontec · wcb6200q firmwareJun 18, 2024
- CVE-2024-614235Monitor
Actiontec WCB6200Q uh_tcp_recv_content Buffer Overflow Remote Code Execution Vulnerability
HighCVSS 8.8No exploitEPSS 1%actiontec · wcb6200q firmwareJun 18, 2024
- CVE-2024-614435Monitor
Actiontec WCB6200Q Multipart Boundary Stack-based Buffer Overflow Remote Code Execution Vulnerability
HighCVSS 8.8No exploitEPSS 1%actiontec · wcb6200q firmwareJun 18, 2024
- CVE-2024-614635Monitor
Actiontec WCB6200Q uh_get_postdata_withupload Stack-based Buffer Overflow Remote Code Execution Vulnerability
HighCVSS 8.8No exploitEPSS 1%actiontec · wcb6200q firmwareJun 18, 2024
- CVE-2024-614335Monitor
Actiontec WCB6200Q uh_tcp_recv_header Buffer Overflow Remote Code Execution Vulnerability
HighCVSS 8.8No exploitEPSS 1%actiontec · wcb6200q firmwareJun 18, 2024
- CVE-2015-290433Monitor
Actiontec GT784WN modems with firmware before NCS01-1.0.13 have hardcoded credentials, which makes it easier for remote attackers to obtain
HighCVSS 8.3No exploitEPSS 1%actiontec · ncs01 firmwareAug 23, 2015
- CVE-2018-1025232Monitor
An issue was discovered on Actiontec WCB6200Q before 1.1.10.20a devices.
HighCVSS 8.1No exploitEPSS 1%actiontec · wcb6200q firmwareMay 14, 2018
- CVE-2015-290527Monitor
Cross-site request forgery (CSRF) vulnerability on Actiontec GT784WN modems with firmware before NCS01-1.0.13 allows remote attackers to hij
MediumCVSS 6.8No exploitEPSS 1%actiontec · ncs01 firmwareAug 23, 2015
- CVE-2019-1278927Monitor
An issue was discovered on Actiontec T2200H T2200H-31.128L.08 devices, as distributed by Telus.
MediumCVSS 6.8No exploitEPSS 1%actiontec · t2200h firmwareJun 17, 2019
- CVE-2013-309724Monitor
Unspecified Cross-site scripting (XSS) vulnerability in the Verizon FIOS Actiontec MI424WR-GEN3I router.
MediumCVSS 6.1No exploitEPSS 1%actiontec · mi424wr-gen3i firmwareNov 13, 2019
- CVE-2018-1992224Monitor
Persistent Cross-Site Scripting (XSS) in the advancedsetup_websiteblocking.html Website Blocking page of the Actiontec C1000A router with fi
MediumCVSS 6.1No exploitEPSS 1%actiontec · c1000a firmwareDec 6, 2018