VYPR
Vendor

Vonage

Products
3
CVEs
5
Across products
5
Status
Private

Products

3

Recent CVEs

5
CVESevRiskCVSSEPSSKEVPublishedDescription
CVE-2017-16902Hig0.537.50.18Nov 20, 2017On the Vonage VDV-23 115 3.2.11-0.9.40 home router, sending a long string of characters in the loginPassword and/or loginUsername field to goform/login causes the router to reboot.
CVE-2017-16843Med0.385.40.00Nov 16, 2017Vonage VDV-23 115 3.2.11-0.9.40 devices have stored XSS via the NewKeyword or NewDomain field to /goform/RgParentalBasic.
CVE-2007-57910.000.04Nov 1, 2007The Vonage Motorola Phone Adapter VT 2142-VD does not properly verify that a SIP INVITE message originated from a legitimate server, which allows remote attackers to send spoofed INVITE messages, as demonstrated by a flood of messages triggering a denial of service, and by phone calls with malicious content.
CVE-2007-57920.000.00Nov 1, 2007The Vonage Motorola Phone Adapter VT 2142-VD does not encrypt RTP packets, which might allow remote attackers to eavesdrop by sniffing the network and reconstructing the RTP session.
CVE-2007-30470.000.01Jun 5, 2007The Vonage VoIP Telephone Adapter has a default administrator username "user" and password "user," which allows remote attackers to obtain administrative access.