Vulnerabilities > Technicolor

DATE CVE VULNERABILITY TITLE RISK
2022-06-12 CVE-2018-25034 Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Technicolor Thomson Tcw710 Firmware St5D.10.05
A vulnerability, which was classified as problematic, has been found in Thomson TCW710 ST5D.10.05.
network
low complexity
technicolor CWE-80
5.4
2022-06-12 CVE-2018-25035 Cross-site Scripting vulnerability in Technicolor Thomson Tcw710 Firmware St5D.10.05
A vulnerability, which was classified as problematic, was found in Thomson TCW710 ST5D.10.05.
3.5
2022-06-12 CVE-2018-25036 Cross-site Scripting vulnerability in Technicolor Thomson Tcw710 Firmware St5D.10.05
A vulnerability has been found in Thomson TCW710 ST5D.10.05 and classified as problematic.
3.5
2022-06-12 CVE-2018-25037 Cross-site Scripting vulnerability in Technicolor Thomson Tcw710 Firmware St5D.10.05
A vulnerability was found in Thomson TCW710 ST5D.10.05 and classified as problematic.
3.5
2022-06-12 CVE-2018-25038 Cross-site Scripting vulnerability in Technicolor Thomson Tcw710 Firmware St5D.10.05
A vulnerability was found in Thomson TCW710 ST5D.10.05.
3.5
2022-06-12 CVE-2018-25039 Cross-site Scripting vulnerability in Technicolor Thomson Tcw710 Firmware St5D.10.05
A vulnerability was found in Thomson TCW710 ST5D.10.05.
3.5
2020-04-01 CVE-2020-11449 Insufficiently Protected Credentials vulnerability in Technicolor Tc7337 Firmware 8.89.17
An issue was discovered on Technicolor TC7337 8.89.17 devices.
network
low complexity
technicolor CWE-522
5.0
2020-03-11 CVE-2020-10376 Cleartext Transmission of Sensitive Information vulnerability in Technicolor Tc7337Net Firmware 08.89.17.23.03
Technicolor TC7337NET 08.89.17.23.03 devices allow remote attackers to discover passwords by sniffing the network for an "Authorization: Basic" HTTP header.
network
low complexity
technicolor CWE-319
5.0
2020-01-09 CVE-2019-19494 Classic Buffer Overflow vulnerability in multiple products
Broadcom based cable modems across multiple vendors are vulnerable to a buffer overflow, which allows a remote attacker to execute arbitrary code at the kernel level via JavaScript run in a victim's browser.
9.3
2020-01-08 CVE-2019-19495 Improper Input Validation vulnerability in Technicolor Tc7230 Steb Firmware 0.1.25
The web interface on the Technicolor TC7230 STEB 01.25 is vulnerable to DNS rebinding, which allows a remote attacker to configure the cable modem via JavaScript in a victim's browser.
network
low complexity
technicolor CWE-20
critical
10.0