Sagemcom records
9 published records for vendor sagemcom.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 1 · 11.1%
- Pre-auth RCE
- 2
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-120 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')3
- CWE-306 Missing Authentication for Critical Function1
- CWE-331 Insufficient Entropy1
- CWE-400 Uncontrolled Resource Consumption1
- CWE-502 Deserialization of Untrusted Data1
- CWE-613 Insufficient Session Expiration1
The weakness classes this vendor ships most often: where to look.
CWEAll records
9 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
42Plan | CVE-2019-19494Weaponized | Broadcom based cable modems across multiple vendors are vulnerable to a buffer overflow, which allows a remote attacker to execute arbitrarysagemcom · f\@st 3890 firmware · CWE-120 | High8.8 | — | 23.1% | Jan 9, 2020 |
39Monitor | CVE-2021-3304No exploit | Sagemcom F@ST 3686 v2 3.495 devices have a buffer overflow via a long sessionKey to the goform/login URI.sagemcom · f\@st 3686 firmware · CWE-120 | Critical9.8 | — | 1.6% | Jan 26, 2021 |
39Monitor | CVE-2025-29329No exploit | Buffer Overflow in the ippprint (Internet Printing Protocol) service in Sagemcom F@st 3686 MAGYAR_4.121.0 allows remote attacker to execute sagemcom · f\@st 3686 firmware · CWE-120 | Critical9.8 | — | 1.0% | Jan 12, 2026 |
36Monitor | CVE-2020-24034No exploit | Sagemcom F@ST 5280 routers using firmware version 1.150.61 have insecure deserialization that allows any authenticated user to perform a prisagemcom · f\@st 5280 router firmware · CWE-502 | High8.8 | — | 3.7% | Sep 1, 2020 |
31Monitor | CVE-2017-6552Proof of concept | Livebox 3 Sagemcom SG30_sip-fr-5.15.8.1 devices have an insufficiently large default value for the maximum IPv6 routing table size: it can bsagemcom · livebox firmware · CWE-400 | High7.5 | — | 4.6% | Mar 9, 2017 |
31Monitor | CVE-2024-1623No exploit | Insufficient session timeout vulnerability in Sagemcom routersagemcom · f\@st 3686 firmware · CWE-613 | High7.8 | — | 0.2% | Mar 14, 2024 |
24Monitor | CVE-2020-21733No exploit | Sagemcom F@ST3686 v1.0 HUN 3.97.0 has XSS via RgDiagnostics.asp, RgDdns.asp, RgFirewallEL.asp, RgVpnL2tpPptp.asp.sagemcom · f\@st 3686 firmware · CWE-79 | Medium6.1 | — | 0.7% | Sep 14, 2020 |
21Monitor | CVE-2020-29138No exploit | Incorrect Access Control in the configuration backup path in SAGEMCOM F@ST3486 NET DOCSIS 3.0, software NET_4.109.0, allows remote unauthentsagemcom · f\@st 3486 router firmware · CWE-306 | Medium5.3 | — | 1.1% | Nov 27, 2020 |
21Monitor | CVE-2019-9555No exploit | Sagemcom F@st 5260 routers using firmware version 0.4.39, in WPA mode, default to using a PSK that is generated from a 2-part wordlist of knsagemcom · f\@st 5260 firmware · CWE-331 | Medium5.3 | — | 1.1% | Mar 5, 2019 |
- CVE-2019-1949442Plan
Broadcom based cable modems across multiple vendors are vulnerable to a buffer overflow, which allows a remote attacker to execute arbitrary
HighCVSS 8.8WeaponizedEPSS 23%sagemcom · f\@st 3890 firmwareJan 9, 2020
- CVE-2021-330439Monitor
Sagemcom F@ST 3686 v2 3.495 devices have a buffer overflow via a long sessionKey to the goform/login URI.
CriticalCVSS 9.8No exploitEPSS 2%sagemcom · f\@st 3686 firmwareJan 26, 2021
- CVE-2025-2932939Monitor
Buffer Overflow in the ippprint (Internet Printing Protocol) service in Sagemcom F@st 3686 MAGYAR_4.121.0 allows remote attacker to execute
CriticalCVSS 9.8No exploitEPSS 1%sagemcom · f\@st 3686 firmwareJan 12, 2026
- CVE-2020-2403436Monitor
Sagemcom F@ST 5280 routers using firmware version 1.150.61 have insecure deserialization that allows any authenticated user to perform a pri
HighCVSS 8.8No exploitEPSS 4%sagemcom · f\@st 5280 router firmwareSep 1, 2020
- CVE-2017-655231Monitor
Livebox 3 Sagemcom SG30_sip-fr-5.15.8.1 devices have an insufficiently large default value for the maximum IPv6 routing table size: it can b
HighCVSS 7.5Proof of conceptEPSS 5%sagemcom · livebox firmwareMar 9, 2017
- CVE-2024-162331Monitor
Insufficient session timeout vulnerability in Sagemcom router
HighCVSS 7.8No exploitEPSS 0%sagemcom · f\@st 3686 firmwareMar 14, 2024
- CVE-2020-2173324Monitor
Sagemcom F@ST3686 v1.0 HUN 3.97.0 has XSS via RgDiagnostics.asp, RgDdns.asp, RgFirewallEL.asp, RgVpnL2tpPptp.asp.
MediumCVSS 6.1No exploitEPSS 1%sagemcom · f\@st 3686 firmwareSep 14, 2020
- CVE-2020-2913821Monitor
Incorrect Access Control in the configuration backup path in SAGEMCOM F@ST3486 NET DOCSIS 3.0, software NET_4.109.0, allows remote unauthent
MediumCVSS 5.3No exploitEPSS 1%sagemcom · f\@st 3486 router firmwareNov 27, 2020
- CVE-2019-955521Monitor
Sagemcom F@st 5260 routers using firmware version 0.4.39, in WPA mode, default to using a PSK that is generated from a 2-part wordlist of kn
MediumCVSS 5.3No exploitEPSS 1%sagemcom · f\@st 5260 firmwareMar 5, 2019