Askey manufactures a focused line of wireless access points and network appliances, primarily its AP5100W and AP4000W series, which serve as infrastructure components in enterprise and carrier deployments. The vendor's vulnerability profile skews strongly toward critical-severity outcomes and clusters around OS command injection, improper input validation, and weak default-configuration issues that are typical of embedded network devices with limited validation on administrative inputs. Live severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Askey over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-15357CRITICAL Network Analysis functionality in Askey AP5100W_Dual_SIG_1.01.097 and all prior versions allows remote attackers to execute arbitrary commands via a shell metacharacter in the ping | Dec 11, 2020 | 9.8 | 30 | NO | NO |
CVE-2020-26201CRITICAL Askey AP5100W_Dual_SIG_1.01.097 and all prior versions use a weak password at the Operating System (rlx-linux) level. This allows an attacker to gain unauthorized access as an admi | Dec 10, 2020 | 9.8 | 29 | NO | NO |
CVE-2020-28695HIGH Askey Fiber Router RTF3505VW-N1 BR_SV_g000_R3505VWN1001_s32_7 devices allow Remote Code Execution and retrieval of admin credentials to log into the Dashboard or login via SSH, lea | Mar 26, 2021 | 8.8 | 27 | NO | NO |
CVE-2020-8614CRITICAL An issue was discovered on Askey AP4000W TDC_V1.01.003 devices. An attacker can perform Remote Code Execution (RCE) by sending a specially crafted network packer to the bd_svr serv | Feb 13, 2020 | 9.8 | 26 | NO | NO |
CVE-2022-47040HIGH An issue in ASKEY router RTF3505VW-N1 BR_SV_g000_R3505VMN1001_s32_7 allows attackers to escalate privileges via running the tcpdump command after placing a crafted file in the /tmp | Jan 26, 2023 | 7.8 | 20 | NO | NO |
CVE-2020-15023MEDIUM Askey AP5100W devices through AP5100W_Dual_SIG_1.01.097 are affected by WPS PIN offline brute-force cracking. This arises because of issues with the random number selection for the | Dec 11, 2020 | 5.9 | 20 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Askey.
Media articles that mention a CVE ID that affects a product developed by Askey — matched by CVE ID, not by vendor name.