Alliedtelesis manufactures networking hardware including routers and switches such as the CentreCom AR series and AT-series platforms, where reported vulnerabilities center on authentication bypass, path traversal, cross-site scripting, OS command injection, and memory-safety issues affecting both device firmware and web-management interfaces. These weakness classes are characteristic of embedded networking appliances with legacy web administration surfaces, and defenders should prioritize access restrictions for management functions on these devices. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Alliedtelesis over time
Signals from CVEs in this vendor scope (8 CVEs).
8 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-18922HIGH A Directory Traversal in the Web interface of the Allied Telesis AT-GS950/8 until Firmware AT-S107 V.1.1.3 [1.00.047] allows unauthenticated attackers to read arbitrary system file | Nov 29, 2019 | 7.5 | 48 | NO | YES |
CVE-2014-1982HIGH The administrative interface in Allied Telesis AT-RG634A ADSL Broadband router 3.3+, iMG624A firmware 3.5, iMG616LH firmware 2.4, and iMG646BD firmware 3.5 allows remote attackers | Mar 31, 2014 | 10.0 | 46 | NO | YES |
CVE-2022-38394CRITICAL Use of hard-coded credentials for the telnet server of CentreCOM AR260S V2 firmware versions prior to Ver.3.3.7 allows a remote unauthenticated attacker to execute an arbitrary OS | Sep 8, 2022 | 9.8 | 31 | NO | NO |
CVE-2018-20503MEDIUM Allied Telesis 8100L/8 devices allow XSS via the edit-ipv4_interface.php vlanid or subnet_mask parameter. | May 7, 2019 | 6.1 | 31 | NO | YES |
CVE-2022-35273HIGH OS command injection vulnerability in GUI setting page of CentreCOM AR260S V2 firmware versions prior to Ver.3.3.7 allows a remote authenticated attacker to execute an arbitrary OS | Sep 8, 2022 | 8.8 | 28 | NO | NO |
CVE-2022-34869HIGH Undocumented hidden command that can be executed from the telnet function of CentreCOM AR260S V2 firmware versions prior to Ver.3.3.7 allows a remote authenticated attacker to exec | Sep 8, 2022 | 8.8 | 28 | NO | NO |
CVE-2014-7249HIGH Buffer overflow on the Allied Telesis AR440S, AR441S, AR442S, AR745, AR750S, AR750S-DP, AT-8624POE, AT-8624T/2M, AT-8648T/2SP, AT-8748XL, AT-8848, AT-9816GB, AT-9924T, AT-9924Ts, C | Dec 19, 2014 | 10.0 | 27 | NO | NO |
CVE-2022-38094HIGH OS command injection vulnerability in the telnet function of CentreCOM AR260S V2 firmware versions prior to Ver.3.3.7 allows a remote authenticated attacker to execute an arbitrary | Sep 8, 2022 | 8.8 | 22 | NO | NO |
Signals from CVEs in this vendor scope (8 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Alliedtelesis.
Media articles that mention a CVE ID that affects a product developed by Alliedtelesis — matched by CVE ID, not by vendor name.