quectel records
4 published records for vendor quectel.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 3
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')3
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
4 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
40Plan | CVE-2023-26921No exploit | OS Command Injection vulnerability in quectel AG550QCN allows attackers to execute arbitrary commands via ql_atfwd.quectel · ag550qcn firmware · CWE-78 | Critical9.8 | — | 2.7% | Apr 4, 2023 |
40Plan | CVE-2022-26147No exploit | The Quectel RG502Q-EA modem before 2022-02-23 allow OS Command Injection.quectel · rg502q-ea firmware · CWE-78 | Critical9.8 | — | 2.7% | Jun 21, 2022 |
40Plan | CVE-2021-31698No exploit | Quectel EG25-G devices through 202006130814 allow executing arbitrary code remotely by using an AT command to place shell metacharacters in quectel · eg25-g firmware · CWE-78 | Critical9.8 | — | 2.0% | Aug 12, 2021 |
24Monitor | CVE-2021-45815No exploit | Quectel UC20 UMTS/HSPA+ UC20 6.3.14 is affected by a Cross Site Scripting (XSS) vulnerability.quectel · uc20 firmware · CWE-79 | Medium6.1 | — | 0.6% | Dec 30, 2021 |
- CVE-2023-2692140Plan
OS Command Injection vulnerability in quectel AG550QCN allows attackers to execute arbitrary commands via ql_atfwd.
CriticalCVSS 9.8No exploitEPSS 3%quectel · ag550qcn firmwareApr 4, 2023
- CVE-2022-2614740Plan
The Quectel RG502Q-EA modem before 2022-02-23 allow OS Command Injection.
CriticalCVSS 9.8No exploitEPSS 3%quectel · rg502q-ea firmwareJun 21, 2022
- CVE-2021-3169840Plan
Quectel EG25-G devices through 202006130814 allow executing arbitrary code remotely by using an AT command to place shell metacharacters in
CriticalCVSS 9.8No exploitEPSS 2%quectel · eg25-g firmwareAug 12, 2021
- CVE-2021-4581524Monitor
Quectel UC20 UMTS/HSPA+ UC20 6.3.14 is affected by a Cross Site Scripting (XSS) vulnerability.
MediumCVSS 6.1No exploitEPSS 1%quectel · uc20 firmwareDec 30, 2021