AT&T's vulnerability profile encompasses a relatively focused but strategically important portfolio centered on consumer and enterprise telecommunications infrastructure, including set-top box firmware, remote-access software, and legacy server components. Vulnerabilities affecting the vendor skew strongly toward critical-severity outcomes and frequently acquire public exploit tooling, creating elevated risk across deployed instances. The exposure recurs persistently through memory-safety weaknesses—out-of-bounds writes, heap-based buffer overflows, and classic buffer-overflow conditions—alongside hard-coded credentials, patterns endemic to embedded firmware and older native applications with limited security-maintenance cycles. Defenders should prioritize inventory and patching of U-Verse and other consumer-endpoint firmware, as well as scrutiny of legacy remote-access and server products still present in enterprise environments. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Att over time
Signals from CVEs in this vendor scope (29 CVEs).
29 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2001-0168HIGH Buffer overflow in AT&T WinVNC (Virtual Network Computing) server 3.3.3r7 and earlier allows remote attackers to execute arbitrary commands via a long HTTP GET request when the Deb | May 3, 2001 | 10.0 | 80 | NO | YES |
CVE-2001-0167HIGH Buffer overflow in AT&T WinVNC (Virtual Network Computing) client 3.3.3r7 and earlier allows remote attackers to execute arbitrary commands via a long rfbConnFailed packet with a l | May 3, 2001 | 7.6 | 65 | NO | YES |
CVE-2017-14117MEDIUM The AT&T U-verse 9.2.2h0d83 firmware for the Arris NVG589 and NVG599 devices, when IP Passthrough mode is not used, configures an unauthenticated proxy service on WAN TCP port 4915 | Sep 3, 2017 | 5.9 | 32 | NO | YES |
CVE-2022-26507CRITICAL A heap-based buffer overflow exists in XML Decompression DecodeTreeBlock in AT&T Labs Xmill 0.7. A crafted input file can lead to remote code execution. This is not the same as any | Apr 14, 2022 | 9.8 | 31 | NO | NO |
CVE-2021-21828CRITICAL A heap-based buffer overflow vulnerability exists in the XML Decompression DecodeTreeBlock functionality of AT&T Labs Xmill 0.7. In the default case of DecodeTreeBlock a label is c | Aug 20, 2021 | 9.8 | 31 | NO | NO |
CVE-2021-21830CRITICAL A heap-based buffer overflow vulnerability exists in the XML Decompression LabelDict::Load functionality of AT&T Labs’ Xmill 0.7. A specially crafted XMI file can lead to remote co | Aug 13, 2021 | 9.8 | 31 | NO | NO |
CVE-2021-21829CRITICAL A heap-based buffer overflow vulnerability exists in the XML Decompression EnumerationUncompressor::UncompressItem functionality of AT&T Labs’ Xmill 0.7. A specially crafted XMI fi | Aug 13, 2021 | 9.8 | 31 | NO | NO |
CVE-2021-21827CRITICAL A heap-based buffer overflow vulnerability exists in the XML Decompression DecodeTreeBlock functionality of AT&T Labs Xmill 0.7. Within `DecodeTreeBlock` which is called during the | Aug 20, 2021 | 9.8 | 30 | NO | NO |
CVE-2021-21826CRITICAL A heap-based buffer overflow vulnerability exists in the XML Decompression DecodeTreeBlock functionality of AT&T Labs Xmill 0.7. Within `DecodeTreeBlock` which is called during the | Aug 20, 2021 | 9.8 | 30 | NO | NO |
CVE-2021-21825CRITICAL A heap-based buffer overflow vulnerability exists in the XML Decompression PlainTextUncompressor::UncompressItem functionality of AT&T Labs’ Xmill 0.7. A specially crafted XMI file | Aug 18, 2021 | 9.8 | 30 | NO | NO |
Signals from CVEs in this vendor scope (29 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Att.
Media articles that mention a CVE ID that affects a product developed by Att — matched by CVE ID, not by vendor name.