VYPR
Vendor

Fastweb

Products
8
CVEs
6
Across products
13
Status
Private

Products

8

Recent CVEs

6
  • CVE-2019-12489CriNov 26, 2019
    risk 0.64cvss 9.8epss 0.06

    An issue was discovered on Fastweb Askey RTV1907VW 0.00.81_FW_200_Askey 2018-10-02 18:08:18 devices. By using the usb_remove service through an HTTP request, it is possible to inject and execute a command between two & characters in the mount parameter.

  • CVE-2018-20122CriFeb 21, 2019
    risk 0.64cvss 9.8epss 0.05

    The web interface on FASTGate Fastweb devices with firmware through 0.00.47_FW_200_Askey 2017-05-17 (software through 1.0.1b) exposed a CGI binary that is vulnerable to a command injection vulnerability that can be exploited to achieve remote code execution with root privileges.…

  • CVE-2018-6023HigMay 11, 2018
    risk 0.60cvss 8.8epss 0.02

    Fastweb FASTgate 0.00.47 devices are vulnerable to CSRF, with impacts including Wi-Fi password changing, Guest Wi-Fi activating, etc.

  • CVE-2020-13620HigNov 24, 2020
    risk 0.57cvss 8.8epss 0.01

    Fastweb FASTGate GPON FGA2130FWB devices through 2020-05-26 allow CSRF via the router administration web panel, leading to an attacker's ability to perform administrative actions such as modifying the configuration.

  • CVE-2022-30114HigMay 19, 2023
    risk 0.49cvss 7.5epss 0.02

    A heap-based buffer overflow in a network service in Fastweb FASTGate MediaAccess FGA2130FWB, firmware version 18.3.n.0482_FW_230_FGA2130, and DGA4131FWB, firmware version up to 18.3.n.0462_FW_261_DGA4131, allows a remote attacker to reboot the device through a crafted HTTP…

  • CVE-2019-18661HigNov 2, 2019
    risk 0.49cvss 7.5epss 0.02

    Fastweb FASTGate 1.0.1b devices allow partial authentication bypass by changing a certain check_pwd return value from 0 to 1. An attack does not achieve administrative control of a device; however, the attacker can view all of the web pages of the administration console.