Vulnerabilities > Swisscom

DATE CVE VULNERABILITY TITLE RISK
2020-08-04 CVE-2020-16134 Unspecified vulnerability in Swisscom products
An issue was discovered on Swisscom Internet Box 2, Internet Box Standard, Internet Box Plus prior to 10.04.38, Internet Box 3 prior to 11.01.20, and Internet Box light prior to 08.06.06.
low complexity
swisscom
8.0
2020-03-16 CVE-2019-19942 Improper Input Validation vulnerability in Swisscom Centro Business and Centro Grande Firmware
Missing output sanitation in Swisscom Centro Grande Centro Grande before 6.16.12, Centro Business 1.0 (ADB) before 7.10.18, and Centro Business 2.0 before 8.02.04 allows a remote attacker to perform DNS spoofing against the web interface via crafted hostnames in DHCP requests.
network
low complexity
swisscom CWE-20
7.5
2020-03-16 CVE-2019-19941 Cross-site Scripting vulnerability in Swisscom Centro Grande Firmware 6.12.02/6.14.00
Missing hostname validation in Swisscom Centro Grande before 6.16.12 allows a remote attacker to inject its local IP address as a domain entry in the DNS service of the router via crafted hostnames in DHCP requests, causing XSS.
network
low complexity
swisscom CWE-79
5.4
2020-03-16 CVE-2019-19940 OS Command Injection vulnerability in Swisscom Centro Grande Firmware 6.12.02/6.14.00
Incorrect input sanitation in text-oriented user interfaces (telnet, ssh) in Swisscom Centro Grande before 6.16.12 allows remote authenticated users to execute arbitrary commands via command injection.
network
low complexity
swisscom CWE-78
7.2
2018-12-17 CVE-2018-16596 Out-of-bounds Write vulnerability in Swisscom products
A stack-based buffer overflow in the LAN UPnP service running on UDP port 1900 of Swisscom Internet-Box (2, Standard, and Plus) prior to v09.04.00 and Internet-Box light prior to v08.05.02 allows remote code execution.
high complexity
swisscom CWE-787
7.5
2018-09-18 CVE-2018-16225 Cleartext Transmission of Sensitive Information vulnerability in multiple products
The QBee MultiSensor Camera through 4.16.4 accepts unencrypted network traffic from clients (such as the QBee Cam application through 1.0.5 for Android and the Swisscom Home application up to 10.7.2 for Android), which results in an attacker being able to reuse cookies to bypass authentication and disable the camera.
low complexity
qbeecam swisscom CWE-319
6.5
2018-03-27 CVE-2018-6766 Uncontrolled Search Path Element vulnerability in Swisscom Tvmediahelper 1.1.0.50
Swisscom TVMediaHelper 1.1.0.50 contains a vulnerability that could allow an unauthenticated, remote attacker to execute arbitrary code on the targeted system.
local
low complexity
swisscom CWE-427
7.8
2018-03-27 CVE-2018-6765 Uncontrolled Search Path Element vulnerability in Swisscom Myswisscomassistant 2.17.1.1065
Swisscom MySwisscomAssistant 2.17.1.1065 contains a vulnerability that could allow an unauthenticated, remote attacker to execute arbitrary code on the targeted system.
local
low complexity
swisscom CWE-427
7.8