Vulnerabilities > Alcatel > High

DATE CVE VULNERABILITY TITLE RISK
2018-08-29 CVE-2018-6597 Unspecified vulnerability in Alcatel A30 Firmware 7.0
The Alcatel A30 device with a build fingerprint of TCL/5046G/MICKEY6US:7.0/NRD90M/J63:user/release-keys contains a hidden privilege escalation capability to achieve command execution as the root user.
local
low complexity
alcatel
7.2
2011-11-22 CVE-2011-4505 Configuration vulnerability in Alcatel products
The UPnP IGD implementation on SpeedTouch 5x6 devices with firmware before 6.2.29 allows remote attackers to establish arbitrary port mappings by sending a UPnP AddPortMapping action in a SOAP request to the WAN interface, related to an "external forwarding" vulnerability.
network
low complexity
alcatel CWE-16
7.5
2001-12-31 CVE-2001-1484 Remote Security vulnerability in Adsl Modem 1000
Alcatel ADSL modems allow remote attackers to access the Trivial File Transfer Protocol (TFTP) to modify firmware and configuration via a bounce attack from a system on the local area network (LAN) side, which is allowed to access TFTP without authentication.
network
low complexity
alcatel
7.5
2001-04-10 CVE-2001-1426 Unspecified vulnerability in Alcatel Speed Touch Home
Alcatel Speed Touch running firmware KHDSAA.108 and KHDSAA.132 through KHDSAA.134 has a TFTP server running without a password, which allows remote attackers to change firmware versions or the device's configurations.
network
low complexity
alcatel
7.5
2001-04-10 CVE-2001-1425 Unspecified vulnerability in Alcatel Speed Touch Home
The challenge-response authentication of the EXPERT user for Alcatel Speed Touch running firmware KHDSAA.108 and KHDSAA.132 through KHDSAA.134 allows remote attackers to gain privileges by directly computing the response based on information that is provided by the device during login.
network
low complexity
alcatel
7.5
2001-04-10 CVE-2001-1424 Unspecified vulnerability in Alcatel Speed Touch Home
Alcatel Speed Touch ADSL modem running firmware KHDSAA.108, KHDSAA.132, KHDSBA.133, and KHDSAA.134 has a blank default password, which allows remote attackers to gain unauthorized access.
network
low complexity
alcatel
7.5