Vulnerabilities > Vonage

DATE CVE VULNERABILITY TITLE RISK
2023-12-05 CVE-2023-47304 Improper Authentication vulnerability in Vonage Vdv23 Firmware Vdv213.2.110.5.1
An issue was discovered in Vonage Box Telephone Adapter VDV23 version VDV21-3.2.11-0.5.1, allows local attackers to bypass UART authentication controls and read/write arbitrary values to the memory of the device.
local
low complexity
vonage CWE-287
7.8
2017-11-20 CVE-2017-16902 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Vonage Vdv-23 Firmware 3.2.110.9.40
On the Vonage VDV-23 115 3.2.11-0.9.40 home router, sending a long string of characters in the loginPassword and/or loginUsername field to goform/login causes the router to reboot.
network
low complexity
vonage CWE-119
7.8
2017-11-16 CVE-2017-16843 Cross-site Scripting vulnerability in Vonage Vdv-23 Firmware 3.2.110.9.40
Vonage VDV-23 115 3.2.11-0.9.40 devices have stored XSS via the NewKeyword or NewDomain field to /goform/RgParentalBasic.
network
vonage CWE-79
3.5
2007-06-05 CVE-2007-3047 Remote Security vulnerability in Voip Telephone Adapter
The Vonage VoIP Telephone Adapter has a default administrator username "user" and password "user," which allows remote attackers to obtain administrative access.
network
low complexity
vonage
critical
10.0