Vulnerabilities > Quectel

DATE CVE VULNERABILITY TITLE RISK
2022-06-21 CVE-2022-26147 OS Command Injection vulnerability in Quectel Rg502Q-Ea Firmware
The Quectel RG502Q-EA modem before 2022-02-23 allow OS Command Injection.
network
low complexity
quectel CWE-78
critical
10.0
2021-12-30 CVE-2021-45815 Cross-site Scripting vulnerability in Quectel Uc20 Firmware 6.3.14
Quectel UC20 UMTS/HSPA+ UC20 6.3.14 is affected by a Cross Site Scripting (XSS) vulnerability.
network
quectel CWE-79
4.3
2021-08-12 CVE-2021-31698 OS Command Injection vulnerability in Quectel Eg25-G Firmware
Quectel EG25-G devices through 202006130814 allow executing arbitrary code remotely by using an AT command to place shell metacharacters in quectel_handle_fumo_cfg input in atfwd_daemon.
network
low complexity
quectel CWE-78
critical
10.0