VYPR

T2200H

by Actiontec

CVEs (2)

  • CVE-2018-15553HigAug 20, 2018
    risk 0.57cvss 8.8epss 0.02

    fileshare.cmd on Telus Actiontec T2200H T2200H-31.128L.03 devices allows OS Command Injection via shell metacharacters in the smbdUserid or smbdPasswd field.

  • CVE-2019-12789MedJun 17, 2019
    risk 0.44cvss 6.8epss 0.01

    An issue was discovered on Actiontec T2200H T2200H-31.128L.08 devices, as distributed by Telus. By attaching a UART adapter to the UART pins on the system board, an attacker can use a special key sequence (Ctrl-\) to obtain a shell with root privileges. After gaining root…