Alcatel's vulnerability footprint centers on networking equipment and access devices, including routers such as SpeedTouch and switching infrastructure like OmniSwitch, which occupy network infrastructure and edge roles across enterprise and service-provider deployments. Its disclosures cluster around web-interface and authentication-oriented weakness classes including improper input validation, cross-site scripting, cross-site request forgery, and authentication bypass, reflecting the management and control-plane exposure of network appliances. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Alcatel over time
Signals from CVEs in this vendor scope (14 CVEs).
14 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2008-4383HIGH Stack-based buffer overflow in the Agranet-Emweb embedded management web server in Alcatel OmniSwitch OS7000, OS6600, OS6800, OS6850, and OS9000 Series devices with AoS 5.1 before | Oct 3, 2008 | 10.0 | 30 | NO | NO |
CVE-2002-1272HIGH Alcatel OmniSwitch 7700/7800 switches running AOS 5.1.1 contains a back door telnet server that was intended for development but not removed before distribution, which allows remot | Dec 11, 2002 | 10.0 | 28 | NO | NO |
CVE-2007-5383HIGH The Thomson/Alcatel SpeedTouch 7G router, as used for the BT Home Hub 6.2.6.B and earlier, allows remote attackers on an intranet to bypass authentication and gain administrative a | Oct 12, 2007 | 10.0 | 26 | NO | NO |
CVE-2011-4505HIGH The UPnP IGD implementation on SpeedTouch 5x6 devices with firmware before 6.2.29 allows remote attackers to establish arbitrary port mappings by sending a UPnP AddPortMapping acti | Nov 22, 2011 | 7.5 | 25 | NO | NO |
CVE-2018-6597MEDIUM The Alcatel A30 device with a build fingerprint of TCL/5046G/MICKEY6US:7.0/NRD90M/J63:user/release-keys contains a hidden privilege escalation capability to achieve command executi | Aug 29, 2018 | 6.8 | 23 | NO | NO |
CVE-2001-1484HIGH Alcatel ADSL modems allow remote attackers to access the Trivial File Transfer Protocol (TFTP) to modify firmware and configuration via a bounce attack from a system on the local a | Dec 31, 2001 | 7.5 | 20 | NO | NO |
CVE-2001-1424HIGH Alcatel Speed Touch ADSL modem running firmware KHDSAA.108, KHDSAA.132, KHDSBA.133, and KHDSAA.134 has a blank default password, which allows remote attackers to gain unauthorized | Apr 10, 2001 | 7.5 | 20 | NO | NO |
CVE-2001-1425HIGH The challenge-response authentication of the EXPERT user for Alcatel Speed Touch running firmware KHDSAA.108 and KHDSAA.132 through KHDSAA.134 allows remote attackers to gain privi | Apr 10, 2001 | 7.5 | 20 | NO | NO |
CVE-2001-1426HIGH Alcatel Speed Touch running firmware KHDSAA.108 and KHDSAA.132 through KHDSAA.134 has a TFTP server running without a password, which allows remote attackers to change firmware ver | Apr 10, 2001 | 7.5 | 20 | NO | NO |
CVE-2002-0119MEDIUM Alcatel Speed Touch Home ADSL Modem allows remote attackers to cause a denial of service (reboot) via a network scan with unusual packets, such as nmap with OS detection. | Mar 25, 2002 | 5.0 | 16 | NO | NO |
Signals from CVEs in this vendor scope (14 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Alcatel.
Media articles that mention a CVE ID that affects a product developed by Alcatel — matched by CVE ID, not by vendor name.