Atcom's vulnerability profile centers on a narrow range of networking and appliance products, particularly its NetVolution platform and A10W firmware variants, which serve in edge and access-control roles. The recurring weakness classes—SQL injection, cross-site scripting, and OS command injection—reflect input-handling and neutralization gaps typical of web-exposed appliance interfaces, and the vendor's disclosures show a notable tendency toward public exploit code availability. Live severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Atcom over time
Signals from CVEs in this vendor scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2011-3340HIGH SQL injection vulnerability in ATCOM Netvolution 2.5.8 ASP allows remote attackers to execute arbitrary SQL commands via the Referer HTTP header. | Oct 21, 2011 | 7.5 | 33 | NO | YES |
CVE-2010-4967HIGH SQL injection vulnerability in default.asp in ATCOM Netvolution 2.5.6 allows remote attackers to execute arbitrary SQL commands via the artID parameter. | Oct 21, 2011 | 7.5 | 33 | NO | YES |
CVE-2009-5102HIGH SQL injection vulnerability in default.asp in ATCOM Netvolution 1.0 ASP allows remote attackers to execute arbitrary SQL commands via the bpe_nid parameter. | Oct 21, 2011 | 7.5 | 33 | NO | YES |
CVE-2019-12328HIGH A command injection (missing input validation) issue in the remote phonebook configuration URI in the web interface of the Atcom A10W VoIP phone with firmware 2.6.1a2421 allows an | Jul 22, 2019 | 8.8 | 27 | NO | NO |
CVE-2009-5103MEDIUM Cross-site scripting (XSS) vulnerability in ATCOM Netvolution 1.0 ASP allows remote attackers to inject arbitrary web script or HTML via the email variable. | Oct 21, 2011 | 4.3 | 25 | NO | YES |
CVE-2014-2318HIGH SQL injection vulnerability in ATCOM Netvolution 3 allows remote attackers to execute arbitrary SQL commands via the m parameter. | Mar 11, 2014 | 7.5 | 20 | NO | NO |
CVE-2010-4966MEDIUM Cross-site scripting (XSS) vulnerability in default.asp in ATCOM Netvolution allows remote attackers to inject arbitrary web script or HTML via the query parameter in a Search acti | Oct 21, 2011 | 4.3 | 16 | NO | NO |
Signals from CVEs in this vendor scope (7 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Atcom.
Media articles that mention a CVE ID that affects a product developed by Atcom — matched by CVE ID, not by vendor name.