彙總 avm 相關全部產品的 CVE 與安全漏洞情報,包括 CVSS、EPSS、公開時間與漏洞情報資料。
已披露問題常與 跨站腳本與路徑處理缺陷 相關,可能在 生產負載與軟體部署 場景中帶來 檔案覆寫與工作階段劫持 等暴露風險。
相關漏洞資料主要來源於公開漏洞披露與安全公告,可用於評估歷史漏洞暴露面與修補優先順序。
| CVE | 摘要 | 來源 | 最高 CVSS | EPSS % | 公開時間 | 更新時間 |
|---|---|---|---|---|---|---|
| CVE-2020-26887 | FRITZ!OS before 7.21 on FRITZ!Box devices allows a bypass of a DNS Rebinding protection mechanism. | [email protected] | 7.8 | 1.40% | 2020-10-23 | 2026-06-16 |
| CVE-2017-8087 | Information Leakage in PPPoE Packet Padding in AVM Fritz!Box 7490 with Firmware versions Fritz!OS 6.80 and 6.83 allows physically proximate attackers to view slices of previously transmitted packets or portions of memory via via unspecified vectors. | [email protected] | 2.4 | 0.35% | 2019-10-22 | 2026-06-16 |
| CVE-2014-8872 | Improper Verification of Cryptographic Signature in AVM FRITZ!Box 6810 LTE after firmware 5.22, FRITZ!Box 6840 LTE after firmware 5.23, and other models with firmware 5.50. | [email protected] | 7.8 | 1.50% | 2017-08-28 | 2026-06-16 |
| CVE-2015-7242 | Cross-site scripting (XSS) vulnerability in the Push-Service-Mails feature in AVM FRITZ!OS before 6.30 allows remote attackers to inject arbitrary web script or HTML via the display name in the FROM field of an SIP INVITE message. | [email protected] | 6.1 | 1.52% | 2016-01-12 | 2026-06-16 |
| CVE-2014-8886 | AVM FRITZ!OS before 6.30 extracts the contents of firmware updates before verifying their cryptographic signature, which allows remote attackers to create symlinks or overwrite critical files, and consequently execute arbitrary code, via a crafted firmware image. | [email protected] | 8.1 | 6.14% | 2016-01-08 | 2026-06-16 |
| CVE-2014-9727 | AVM Fritz!Box allows remote attackers to execute arbitrary commands via shell metacharacters in the var:lang parameter to cgi-bin/webcm. | [email protected] | 10.0 | 71.64% | 2015-05-29 | 2026-06-16 |
| CVE-2007-0431 | AVM Fritz!Box 7050, and possibly other product models, allows remote attackers to cause a denial of service (VoIP application crash) via a zero-length UDP packet to the SIP port (port 5060). | [email protected] | 7.8 | 2.35% | 2007-01-22 | 2026-06-16 |
| CVE-2000-0262 | The AVM KEN! ISDN Proxy server allows remote attackers to cause a denial of service via a malformed request. | [email protected] | 5.0 | 7.28% | 2000-04-12 | 2026-06-16 |
| CVE-2000-0261 | The AVM KEN! web server allows remote attackers to read arbitrary files via a .. (dot dot) attack. | [email protected] | 5.0 | 1.59% | 2000-04-12 | 2026-06-16 |