Known Vulnerabilities for products from Avm

Listed below are 9 of the newest known vulnerabilities associated with the vendor "Avm".

These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.

Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.

Additional devices specifications by Avm can be found at device.report : Avm

Known Vulnerabilities

CVE Shortened Description Severity Publish Date Last Modified
CVE-2020-26887 json FRITZ!OS before 7.21 on FRITZ!Box devices allows a bypass of a DNS Rebinding protection mechanism. 7.8 - HIGH 2020-10-23 2020-11-03
CVE-2017-8087 json Information Leakage in PPPoE Packet Padding in AVM Fritz!Box 7490 with Firmware versions Fritz!OS 6.80 and 6.83 allows physic... 2.4 - LOW 2019-10-22 2019-10-24
CVE-2015-7242 json Cross-site scripting (XSS) vulnerability in the Push-Service-Mails feature in AVM FRITZ!OS before 6.30 allows remote attacker... Not Provided 2016-01-12 2026-05-06
CVE-2014-9727 json AVM Fritz!Box allows remote attackers to execute arbitrary commands via shell metacharacters in the var:lang parameter to cgi... Not Provided 2015-05-29 2026-05-06
CVE-2014-8886 json AVM FRITZ!OS before 6.30 extracts the contents of firmware updates before verifying their cryptographic signature, which allo... Not Provided 2016-01-08 2026-05-06
CVE-2014-8872 json Improper Verification of Cryptographic Signature in AVM FRITZ!Box 6810 LTE after firmware 5.22, FRITZ!Box 6840 LTE after firm... 7.8 - HIGH 2017-08-29 2018-10-09
CVE-2007-0431 json AVM Fritz!Box 7050, and possibly other product models, allows remote attackers to cause a denial of service (VoIP application... Not Provided 2007-01-23 2026-04-23
CVE-2000-0262 json The AVM KEN! ISDN Proxy server allows remote attackers to cause a denial of service via a malformed request. Not Provided 2000-04-12 2025-04-03
CVE-2000-0261 json The AVM KEN! web server allows remote attackers to read arbitrary files via a .. (dot dot) attack. Not Provided 2000-04-12 2025-04-03

Known software with vulnerabilities from Avm

Type Vendor Product Version
HardwareAvmFritz!box 7490-
Operating
System
AvmFritz!box 7490 Firmware-
Operating
System
AvmFritz!os6.80
Operating
System
AvmFritz! Os6.23