fastweb CVE Vulnerabilities & CVE List (6)

Products (CPE): — CVEs: 6

fastweb vulnerability overview

Aggregates CVE and security vulnerability intelligence across all fastweb-related products, including CVSS, EPSS, publication dates, and vulnerability intelligence data.

Disclosed issues often relate to vendor risk csrf and vendor risk memory corruption; exposure may include vendor impact memory corruption and vendor impact application crash in vendor surface production workloads contexts.

Vulnerability distribution trend (last 24 months)

Showing 16 of 6 CVEs
«« First « Prev Page 1 / 1 Next »
CVE Summary Source Max CVSS EPSS % Published Updated
CVE-2022-30114 A heap-based buffer overflow in a network service in Fastweb FASTGate MediaAccess FGA2130FWB, firmware version 18.3.n.0482_FW_230_FGA2130, and DGA4131FWB, firmware version up to 18.3.n.0462_FW_261_DGA4131, allows a remote attacker to reboot the device through a crafted HTTP request, causing DoS. [email protected] 7.5 16.55% 2023-05-19 2025-01-21
CVE-2020-13620 Fastweb FASTGate GPON FGA2130FWB devices through 2020-05-26 allow CSRF via the router administration web panel, leading to an attacker's ability to perform administrative actions such as modifying the configuration. [email protected] 8.8 0.14% 2020-11-24 2024-11-21
CVE-2019-12489 An issue was discovered on Fastweb Askey RTV1907VW 0.00.81_FW_200_Askey 2018-10-02 18:08:18 devices. By using the usb_remove service through an HTTP request, it is possible to inject and execute a command between two & characters in the mount parameter. [email protected] 9.8 11.49% 2019-11-26 2024-11-21
CVE-2019-18661 Fastweb FASTGate 1.0.1b devices allow partial authentication bypass by changing a certain check_pwd return value from 0 to 1. An attack does not achieve administrative control of a device; however, the attacker can view all of the web pages of the administration console. [email protected] 7.5 0.24% 2019-11-02 2024-11-21
CVE-2018-20122 The web interface on FASTGate Fastweb devices with firmware through 0.00.47_FW_200_Askey 2017-05-17 (software through 1.0.1b) exposed a CGI binary that is vulnerable to a command injection vulnerability that can be exploited to achieve remote code execution with root privileges. No authentication is required in order to trigger the vulnerability. [email protected] 9.8 6.39% 2019-02-21 2024-11-21
CVE-2018-6023 Fastweb FASTgate 0.00.47 devices are vulnerable to CSRF, with impacts including Wi-Fi password changing, Guest Wi-Fi activating, etc. [email protected] 8.8 0.25% 2018-05-11 2024-11-21
«« First « Prev Page 1 / 1 Next »
cvelogic Threat Intelligence