3Com's vulnerability footprint spans a modest portfolio of networking and security appliances, including load balancers, network access devices, and intrusion-prevention systems that sit on infrastructure boundaries. The exposure concentrates across products such as 3CDaemon, the TippingPoint IPS line, and various wireless access points, with recurring weakness classes centered on input validation, memory-buffer handling, and web-layer encoding issues that are characteristic of embedded network software. Vulnerabilities affecting this vendor frequently acquire public exploit code, reflecting the appeal of network infrastructure for targeted attacks and the long operational lifespans of these devices in fielded networks. The absence of high-severity clustering and limited observed cataloging in known-exploited lists suggests that while exploit tooling circulates, active in-the-wild exploitation tends toward specific deployment contexts rather than broad campaigns. Defenders should inventory 3Com appliances in their network perimeter and prioritize patching those that remain internet-reachable; current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by 3com over time
Signals from CVEs in this vendor scope (41 CVEs).
41 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2006-6183HIGH Multiple stack-based buffer overflows in 3Com 3CTftpSvc 2.0.1, and possibly earlier, allow remote attackers to cause a denial of service (crash) or execute arbitrary code via a lon | Dec 1, 2006 | 10.0 | 81 | NO | YES |
CVE-2005-0277MEDIUM Buffer overflow in the FTP service in 3Com 3CDaemon 2.0 revision 10 allows remote attackers to cause a denial of service (application crash) and execute arbitrary code via (1) a lo | May 2, 2005 | 5.0 | 64 | NO | YES |
CVE-2004-2691HIGH Unspecified vulnerability in 3Com SuperStack 3 4400 switches with firmware version before 3.31 allows remote attackers to cause a denial of service (device reset) via a crafted req | Dec 31, 2004 | 7.1 | 55 | NO | YES |
CVE-2001-1291CRITICAL The telnet server for 3Com hardware such as PS40 SuperStack II does not delay or disconnect remote attackers who provide an incorrect username or password, which makes it easier to | Jul 12, 2001 | 9.8 | 45 | NO | YES |
CVE-2010-2103MEDIUM Cross-site scripting (XSS) vulnerability in axis2-admin/axis2-admin/engagingglobally in the administration console in Apache Axis2/Java 1.4.1, 1.5.1, and possibly other versions, a | May 27, 2010 | 4.3 | 42 | NO | YES |
CVE-2007-3701HIGH TippingPoint IPS before 20070710 does not properly handle a hex-encoded alternate Unicode '/' (slash) character, which might allow remote attackers to send certain network traffic | Jul 11, 2007 | 7.5 | 39 | NO | YES |
CVE-2002-0606HIGH Buffer overflow in 3Cdaemon 2.0 FTP server allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via long commands such as login. | Jun 18, 2002 | 7.5 | 33 | NO | YES |
CVE-2002-2300HIGH Buffer overflow in ftpd 5.4 in 3Com NBX 4.0.17 or ftpd 5.4.2 in 3Com NBX 4.1.4 allows remote attackers to cause a denial of service (crash) via a long CEL command. | Dec 31, 2002 | 7.5 | 30 | NO | YES |
CVE-2005-0419HIGH Multiple heap-based buffer overflows in 3Com 3CServer allow remote authenticated users to execute arbitrary code via long FTP commands, as demonstrated using the STAT command. | Apr 27, 2005 | 7.5 | 29 | NO | YES |
CVE-2004-1596HIGH The 3COM Wireless router 3CRADSL72 running Boot Code 1.3d allows remote attackers to gain sensitive information such as passwords and router settings via a direct HTTP request to a | Oct 13, 2004 | 7.5 | 29 | NO | YES |
Signals from CVEs in this vendor scope (41 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by 3com.
Media articles that mention a CVE ID that affects a product developed by 3com — matched by CVE ID, not by vendor name.