Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Att

First CVE: May 23, 1991Active for: 35 yearsTotal CVEs: 29
54.5
VTI Score
TOP TARGET

AT&T's vulnerability profile encompasses a relatively focused but strategically important portfolio centered on consumer and enterprise telecommunications infrastructure, including set-top box firmware, remote-access software, and legacy server components. Vulnerabilities affecting the vendor skew strongly toward critical-severity outcomes and frequently acquire public exploit tooling, creating elevated risk across deployed instances. The exposure recurs persistently through memory-safety weaknesses—out-of-bounds writes, heap-based buffer overflows, and classic buffer-overflow conditions—alongside hard-coded credentials, patterns endemic to embedded firmware and older native applications with limited security-maintenance cycles. Defenders should prioritize inventory and patching of U-Verse and other consumer-endpoint firmware, as well as scrutiny of legacy remote-access and server products still present in enterprise environments. Current exploitation activity and exposure counts are shown alongside this summary.

FAUCET AI Generated
29
Total CVEs
More Total CVEs than 97% of tracked vendors
0.2
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 2% of tracked vendors
8.3
Avg CVSS Score
Higher Avg CVSS Score than 81% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Att over time

Volume of CVEsAvg CVSS Base Score
First CVE
May 23, 1991
35 years ago
Most Recent CVE
Apr 14, 2022
1,562 days ago

Products(11 total)

Top CVEs

Signals from CVEs in this vendor scope (29 CVEs).

29 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2001-0168HIGH
Buffer overflow in AT&T WinVNC (Virtual Network Computing) server 3.3.3r7 and earlier allows remote attackers to execute arbitrary commands via a long HTTP GET request when the Deb
May 3, 200110.080NOYES
CVE-2001-0167HIGH
Buffer overflow in AT&T WinVNC (Virtual Network Computing) client 3.3.3r7 and earlier allows remote attackers to execute arbitrary commands via a long rfbConnFailed packet with a l
May 3, 20017.665NOYES
CVE-2017-14117MEDIUM
The AT&T U-verse 9.2.2h0d83 firmware for the Arris NVG589 and NVG599 devices, when IP Passthrough mode is not used, configures an unauthenticated proxy service on WAN TCP port 4915
Sep 3, 20175.932NOYES
CVE-2022-26507CRITICAL
A heap-based buffer overflow exists in XML Decompression DecodeTreeBlock in AT&T Labs Xmill 0.7. A crafted input file can lead to remote code execution. This is not the same as any
Apr 14, 20229.831NONO
CVE-2021-21828CRITICAL
A heap-based buffer overflow vulnerability exists in the XML Decompression DecodeTreeBlock functionality of AT&T Labs Xmill 0.7. In the default case of DecodeTreeBlock a label is c
Aug 20, 20219.831NONO
CVE-2021-21830CRITICAL
A heap-based buffer overflow vulnerability exists in the XML Decompression LabelDict::Load functionality of AT&T Labs’ Xmill 0.7. A specially crafted XMI file can lead to remote co
Aug 13, 20219.831NONO
CVE-2021-21829CRITICAL
A heap-based buffer overflow vulnerability exists in the XML Decompression EnumerationUncompressor::UncompressItem functionality of AT&T Labs’ Xmill 0.7. A specially crafted XMI fi
Aug 13, 20219.831NONO
CVE-2021-21827CRITICAL
A heap-based buffer overflow vulnerability exists in the XML Decompression DecodeTreeBlock functionality of AT&T Labs Xmill 0.7. Within `DecodeTreeBlock` which is called during the
Aug 20, 20219.830NONO
CVE-2021-21826CRITICAL
A heap-based buffer overflow vulnerability exists in the XML Decompression DecodeTreeBlock functionality of AT&T Labs Xmill 0.7. Within `DecodeTreeBlock` which is called during the
Aug 20, 20219.830NONO
CVE-2021-21825CRITICAL
A heap-based buffer overflow vulnerability exists in the XML Decompression PlainTextUncompressor::UncompressItem functionality of AT&T Labs’ Xmill 0.7. A specially crafted XMI file
Aug 18, 20219.830NONO
View all 29 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products29 CVEs
14%
55%
31%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local4 (13.8%)
Network15 (51.7%)
Unknown10 (34.5%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low15 (51.7%)
High4 (13.8%)
Unknown10 (34.5%)
User Interaction
None19 (65.5%)
Unknown10 (34.5%)
Required0 (0.0%)
Privileges Required
Low4 (13.8%)
High0 (0.0%)
None15 (51.7%)
Unknown10 (34.5%)

Exploit Exposure

Signals from CVEs in this vendor scope (29 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
3 CVEs
10.3% of CVEs· 98th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
2 CVEs
6.9% of CVEs· 75th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Att.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Att — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Att's Products

View all 3 CNAs →

Top CWEs