Allied Telesis manufactures enterprise networking equipment, with disclosed vulnerabilities centered on its CentreCom AR260S routing appliance and its associated firmware. The observed exposure reflects the network-edge attack surface typical of remotely accessible routing and access-control devices. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Allied Telesis over time
Signals from CVEs in this vendor scope (8 CVEs).
8 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-18922HIGH A Directory Traversal in the Web interface of the Allied Telesis AT-GS950/8 until Firmware AT-S107 V.1.1.3 [1.00.047] allows unauthenticated attackers to read arbitrary system file | Nov 29, 2019 | 7.5 | 48 | NO | YES |
CVE-2014-1982HIGH The administrative interface in Allied Telesis AT-RG634A ADSL Broadband router 3.3+, iMG624A firmware 3.5, iMG616LH firmware 2.4, and iMG646BD firmware 3.5 allows remote attackers | Mar 31, 2014 | 10.0 | 46 | NO | YES |
CVE-2022-38394CRITICAL Use of hard-coded credentials for the telnet server of CentreCOM AR260S V2 firmware versions prior to Ver.3.3.7 allows a remote unauthenticated attacker to execute an arbitrary OS | Sep 8, 2022 | 9.8 | 31 | NO | NO |
CVE-2018-20503MEDIUM Allied Telesis 8100L/8 devices allow XSS via the edit-ipv4_interface.php vlanid or subnet_mask parameter. | May 7, 2019 | 6.1 | 31 | NO | YES |
CVE-2022-35273HIGH OS command injection vulnerability in GUI setting page of CentreCOM AR260S V2 firmware versions prior to Ver.3.3.7 allows a remote authenticated attacker to execute an arbitrary OS | Sep 8, 2022 | 8.8 | 28 | NO | NO |
CVE-2022-34869HIGH Undocumented hidden command that can be executed from the telnet function of CentreCOM AR260S V2 firmware versions prior to Ver.3.3.7 allows a remote authenticated attacker to exec | Sep 8, 2022 | 8.8 | 28 | NO | NO |
CVE-2014-7249HIGH Buffer overflow on the Allied Telesis AR440S, AR441S, AR442S, AR745, AR750S, AR750S-DP, AT-8624POE, AT-8624T/2M, AT-8648T/2SP, AT-8748XL, AT-8848, AT-9816GB, AT-9924T, AT-9924Ts, C | Dec 19, 2014 | 10.0 | 27 | NO | NO |
CVE-2022-38094HIGH OS command injection vulnerability in the telnet function of CentreCOM AR260S V2 firmware versions prior to Ver.3.3.7 allows a remote authenticated attacker to execute an arbitrary | Sep 8, 2022 | 8.8 | 22 | NO | NO |
Signals from CVEs in this vendor scope (8 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Allied Telesis.
Media articles that mention a CVE ID that affects a product developed by Allied Telesis — matched by CVE ID, not by vendor name.