Aztech's vulnerability footprint concentrates in a narrow line of ADSL/DSL modem and gateway devices such as the DSL5018EN and DSL705E, which despite their modest product count occupy a prominent position in the residential networking landscape. Vulnerabilities affecting this vendor skew strongly toward critical severity and frequently acquire public exploit code, clustering around authentication bypass, credential exposure, and command-injection weaknesses that are characteristic of embedded network appliances with legacy firmware architectures. Defenders managing these devices should treat security updates as urgent and inventory end-of-life units that may no longer receive patches; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Aztech over time
Signals from CVEs in this vendor scope (8 CVEs).
8 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2014-6436CRITICAL Aztech ADSL DSL5018EN (1T1R), DSL705E, and DSL705EU devices improperly manage sessions, which allows remote attackers to bypass authentication in opportunistic circumstances and ex | Jan 12, 2018 | 9.8 | 63 | NO | YES |
CVE-2014-6437CRITICAL Aztech ADSL DSL5018EN (1T1R), DSL705E, and DSL705EU devices allow remote attackers to obtain sensitive device configuration information via vectors involving the ROM file. | Jan 12, 2018 | 9.8 | 47 | NO | YES |
CVE-2014-6435HIGH cgi-bin/AZ_Retrain.cgi in Aztech ADSL DSL5018EN (1T1R), DSL705E, and DSL705EU devices does not check for authentication, which allows remote attackers to cause a denial of service | Jan 12, 2018 | 7.5 | 42 | NO | YES |
CVE-2022-45599CRITICAL Aztech WMB250AC Mesh Routers Firmware Version 016 2020 is vulnerable to PHP Type Juggling in file /var/www/login.php, allows attackers to gain escalated privileges only when specif | Feb 22, 2023 | 9.8 | 31 | NO | NO |
CVE-2022-45600HIGH Aztech WMB250AC Mesh Routers Firmware Version 016 2020 devices improperly manage sessions, which allows remote attackers to bypass authentication in opportunistic circumstances and | Feb 22, 2023 | 8.8 | 27 | NO | NO |
CVE-2008-6554HIGH cgi-bin/script in Aztech ADSL2/2+ 4-port router 3.7.0 build 070426 allows remote attackers to execute arbitrary commands via shell metacharacters in the query string. | Mar 30, 2009 | 10.0 | 27 | NO | NO |
CVE-2008-6588HIGH Aztech ADSL2/2+ 4-port router has a default "isp" account with a default "isp" password, which allows remote attackers to obtain access if this default is not changed. | Apr 3, 2009 | 10.0 | 25 | NO | NO |
CVE-2007-4733HIGH The Aztech DSL600EU router, when WAN access to the web interface is disabled, does not properly block inbound traffic on TCP port 80, which allows remote attackers to connect to th | Sep 6, 2007 | 9.3 | 25 | NO | NO |
Signals from CVEs in this vendor scope (8 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Aztech.
Media articles that mention a CVE ID that affects a product developed by Aztech — matched by CVE ID, not by vendor name.