Comtrend records
5 published records for vendor comtrend.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')2
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')2
- CWE-522 Insufficiently Protected Credentials1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
5 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
58Plan | CVE-2020-10173Proof of concept | Comtrend VR-3033 DE11-416SSG-C01_R02.A2pvI042j1.d26m devices have Multiple Authenticated Command Injection vulnerabilities via the ping and comtrend · vr-3033 firmware · CWE-78 | High8.8 | — | 77.1% | Mar 5, 2020 |
39Monitor | CVE-2018-20388No exploit | Comtrend CM-6200un 123.447.007 and CM-6300n 123.553mp1.005 devices allow remote attackers to discover credentials via iso.3.6.1.4.1.4491.2.4comtrend · cm-6200un firmware · CWE-522 | Critical9.8 | — | 1.5% | Dec 23, 2018 |
32Monitor | CVE-2024-5785No exploit | Command injection vulnerability in Comtrend routercomtrend · comtrend wld71-t1_v2.0.201820 · CWE-78 | High8.0 | — | 0.9% | Jun 10, 2024 |
21Monitor | CVE-2018-8062Proof of concept | A cross-site scripting (XSS) vulnerability on Comtrend AR-5387un devices with A731-410JAZ-C04_R02.A2pD035g.d23i firmware allows remote attaccomtrend · ar-5387un firmware · CWE-79 | Medium5.4 | — | 1.0% | Oct 23, 2020 |
17Monitor | CVE-2010-0470Proof of concept | Cross-site scripting (XSS) vulnerability in scvrtsrv.cmd in Comtrend CT-507IT ADSL Router allows remote attackers to inject arbitrary web sccomtrend · ct-507it adsl router · CWE-79 | Medium4.3 | — | 1.5% | Feb 2, 2010 |
- CVE-2020-1017358Plan
Comtrend VR-3033 DE11-416SSG-C01_R02.A2pvI042j1.d26m devices have Multiple Authenticated Command Injection vulnerabilities via the ping and
HighCVSS 8.8Proof of conceptEPSS 77%comtrend · vr-3033 firmwareMar 5, 2020
- CVE-2018-2038839Monitor
Comtrend CM-6200un 123.447.007 and CM-6300n 123.553mp1.005 devices allow remote attackers to discover credentials via iso.3.6.1.4.1.4491.2.4
CriticalCVSS 9.8No exploitEPSS 2%comtrend · cm-6200un firmwareDec 23, 2018
- CVE-2024-578532Monitor
Command injection vulnerability in Comtrend router
HighCVSS 8.0No exploitEPSS 1%comtrend · comtrend wld71-t1_v2.0.201820Jun 10, 2024
- CVE-2018-806221Monitor
A cross-site scripting (XSS) vulnerability on Comtrend AR-5387un devices with A731-410JAZ-C04_R02.A2pD035g.d23i firmware allows remote attac
MediumCVSS 5.4Proof of conceptEPSS 1%comtrend · ar-5387un firmwareOct 23, 2020
- CVE-2010-047017Monitor
Cross-site scripting (XSS) vulnerability in scvrtsrv.cmd in Comtrend CT-507IT ADSL Router allows remote attackers to inject arbitrary web sc
MediumCVSS 4.3Proof of conceptEPSS 1%comtrend · ct-507it adsl routerFeb 2, 2010