2wire manufactures a portfolio of residential and small-business broadband gateway and routing appliances, including models such as the 1701HG and 2700HG that achieved broad deployment across consumer ISP subscriber bases. The vendor's vulnerability profile clusters around web-management interfaces and firmware components affected by input-validation weaknesses, cross-site request forgery, and path-traversal conditions, coupled with a notable tendency toward public exploit availability—a pattern consistent with the appeal of stable, long-lived gateway hardware to security research and network reconnaissance tooling. Current severity, exploitation activity, and detailed exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by 2wire over time
Signals from CVEs in this vendor scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2009-3962HIGH The management interface on the 2wire Gateway 1700HG, 1701HG, 1800HW, 2071, 2700HG, and 2701HG-T with software before 5.29.52 allows remote attackers to cause a denial of service ( | Nov 17, 2009 | 7.8 | 31 | NO | YES |
CVE-2007-4389HIGH Cross-site request forgery (CSRF) vulnerability in /xslt in 2wire 1701HG, 1800HW, and 2071 Gateway routers, with 3.17.5, 3.7.1, and 5.29.51 software, allows remote attackers to cre | Aug 17, 2007 | 7.8 | 29 | NO | YES |
CVE-2007-4387MEDIUM Cross-site request forgery (CSRF) vulnerability in /xslt in 2wire 1701HG and 2071 Gateway routers, with 3.17.5 and 5.29.51 software, allows remote attackers to perform certain conf | Aug 17, 2007 | 4.3 | 28 | NO | YES |
CVE-2008-6605MEDIUM Cross-site request forgery (CSRF) vulnerability in the xslt script in the web-based management interface on the 2wire 1701HG, 1800HW, 2071HG, and 2700HG with firmware 3.17.5, 3.7.1 | Apr 6, 2009 | 6.8 | 26 | NO | YES |
CVE-2004-2749MEDIUM Directory traversal vulnerability in wra/public/wralogin in 2Wire Gateway, possibly as used in HomePortal and other product lines, allows remote attackers to read arbitrary files v | Dec 31, 2004 | 4.3 | 26 | NO | YES |
CVE-2007-4388HIGH 2wire 1701HG and 2071 Gateway routers, with 5.29.51 and possibly 3.17.5 software, have a blank password by default. | Aug 17, 2007 | 10.0 | 25 | NO | NO |
CVE-2006-4523MEDIUM The web-based management interface in 2Wire, Inc. HomePortal and OfficePortal Series modems and routers allows remote attackers to cause a denial of service (crash) via a CRLF sequ | Sep 1, 2006 | 5.0 | 23 | NO | YES |
Signals from CVEs in this vendor scope (7 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by 2wire.
Media articles that mention a CVE ID that affects a product developed by 2wire — matched by CVE ID, not by vendor name.