avm 関連製品全体の CVE とセキュリティ脆弱性情報を集約し、CVSS、EPSS、公開日、脆弱性情報データを掲載しています。
公開された問題は vendor risk cross-site scripting and パス処理の欠陥 に関連することが多く、vendor surface production workloads and vendor surface software deployment の文脈で ファイル上書き and vendor impact session compromise などの暴露リスクを伴う場合があります。
掲載データは公開脆弱性情報とセキュリティ公告に基づき、過去の暴露面と修補優先度の評価に利用できます。
| CVE | 概要 | ソース | CVSS 最大値 | EPSS(%) | 公開 | 更新 |
|---|---|---|---|---|---|---|
| CVE-2020-26887 | FRITZ!OS before 7.21 on FRITZ!Box devices allows a bypass of a DNS Rebinding protection mechanism. | [email protected] | 7.8 | 0.31% | 2020-10-23 | 2024-11-21 |
| CVE-2017-8087 | Information Leakage in PPPoE Packet Padding in AVM Fritz!Box 7490 with Firmware versions Fritz!OS 6.80 and 6.83 allows physically proximate attackers to view slices of previously transmitted packets or portions of memory via via unspecified vectors. | [email protected] | 2.4 | 0.15% | 2019-10-22 | 2024-11-21 |
| CVE-2014-8872 | Improper Verification of Cryptographic Signature in AVM FRITZ!Box 6810 LTE after firmware 5.22, FRITZ!Box 6840 LTE after firmware 5.23, and other models with firmware 5.50. | [email protected] | 7.8 | 0.14% | 2017-08-29 | 2026-05-13 |
| CVE-2015-7242 | Cross-site scripting (XSS) vulnerability in the Push-Service-Mails feature in AVM FRITZ!OS before 6.30 allows remote attackers to inject arbitrary web script or HTML via the display name in the FROM field of an SIP INVITE message. | [email protected] | 6.1 | 0.26% | 2016-01-12 | 2026-05-06 |
| CVE-2014-8886 | AVM FRITZ!OS before 6.30 extracts the contents of firmware updates before verifying their cryptographic signature, which allows remote attackers to create symlinks or overwrite critical files, and consequently execute arbitrary code, via a crafted firmware image. | [email protected] | 8.1 | 4.54% | 2016-01-08 | 2026-05-06 |
| CVE-2014-9727 | AVM Fritz!Box allows remote attackers to execute arbitrary commands via shell metacharacters in the var:lang parameter to cgi-bin/webcm. | [email protected] | 10.0 | 87.77% | 2015-05-29 | 2026-05-06 |
| CVE-2007-0431 | AVM Fritz!Box 7050, and possibly other product models, allows remote attackers to cause a denial of service (VoIP application crash) via a zero-length UDP packet to the SIP port (port 5060). | [email protected] | 7.8 | 3.51% | 2007-01-23 | 2026-04-23 |
| CVE-2000-0262 | The AVM KEN! ISDN Proxy server allows remote attackers to cause a denial of service via a malformed request. | [email protected] | 5.0 | 4.19% | 2000-04-12 | 2026-04-16 |
| CVE-2000-0261 | The AVM KEN! web server allows remote attackers to read arbitrary files via a .. (dot dot) attack. | [email protected] | 5.0 | 0.65% | 2000-04-12 | 2026-04-16 |