Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Cobham

First CVE: Aug 15, 2014Active for: 12 yearsTotal CVEs: 27
25.0
VTI Score
Low

Cobham manufactures maritime communication and satellite systems for the shipping and emergency-response sectors, with vulnerabilities concentrating in its VSAT and emergency-beacon product lines such as the Sailor 600 and Explorer 710 series. The vendor's disclosures skew toward serious outcomes, with a meaningful share reaching critical severity, and reflect the authentication and access-control demands of networked maritime appliances exposed to the open ocean and remote provisioning. Recurring weakness classes include cross-site scripting, sensitive-information exposure, improper access control, and authentication bypass, characteristics typical of web-facing device management interfaces that often ship with default credentials or weak input validation. Defenders managing maritime vessel communication systems should inventory affected terminals and prioritize firmware updates to these communication-critical platforms. Current severity, exploitation activity, and exposure counts are shown alongside this summary.

FAUCET AI Generated
27
Total CVEs
More Total CVEs than 97% of tracked vendors
0.1
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 1% of tracked vendors
7.3
Avg CVSS Score
Higher Avg CVSS Score than 54% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Cobham over time

Volume of CVEsAvg CVSS Base Score
First CVE
Aug 15, 2014
11 years ago
Most Recent CVE
Apr 12, 2024
833 days ago

Products(53 total)

Top CVEs

Signals from CVEs in this vendor scope (27 CVEs).

27 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2018-5267CRITICAL
Cobham Sea Tel 121 build 222701 devices allow remote attackers to bypass authentication via a direct request to MenuDealerGx.html, MenuDealer.html, MenuEuNCGx.html, MenuEuNC.html,
Jan 8, 20189.831NONO
CVE-2019-9531CRITICAL
The web application portal of the Cobham EXPLORER 710, firmware version 1.07, allows unauthenticated access to port 5454. This could allow an unauthenticated, remote attacker to co
Oct 10, 20199.830NONO
CVE-2018-19392CRITICAL
Cobham Satcom Sailor 250 and 500 devices before 1.25 contained an unauthenticated password reset vulnerability. This could allow modification of any user account's password (includ
Mar 15, 20199.829NONO
CVE-2014-2940HIGH
Cobham Sailor 900 and 6000 satellite terminals with firmware 1.08 MFHF and 2.11 VHF have hardcoded credentials for the administrator account, which allows attackers to obtain admin
Aug 15, 201410.025NONO
CVE-2019-9533CRITICAL
The root password of the Cobham EXPLORER 710 is the same for all versions of firmware up to and including v1.08. This could allow an attacker to reverse-engineer the password from
Oct 10, 20199.824NONO
CVE-2018-19393HIGH
Cobham Satcom Sailor 800 and 900 devices contained a vulnerability that allowed for arbitrary writing of content to the system's configuration file. This was exploitable via multip
Mar 15, 20197.524NONO
CVE-2014-0328HIGH
The thraneLINK protocol implementation on Cobham devices does not verify firmware signatures, which allows attackers to execute arbitrary code by leveraging physical access or term
Aug 15, 20149.324NONO
CVE-2013-7180HIGH
Cobham SAILOR 900 VSAT; SAILOR FleetBroadBand 150, 250, and 500; EXPLORER BGAN; and AVIATOR 200, 300, 350, and 700D devices do not properly restrict password recovery, which allows
Aug 15, 20147.824NONO
CVE-2018-5266HIGH
Cobham Sea Tel 121 build 222701 devices allow remote attackers to obtain potentially sensitive information about valid usernames by reading the loginName lines at the js/userLogin.
Jan 8, 20187.523NONO
CVE-2014-2942HIGH
Cobham Aviator 700D and 700E satellite terminals use an improper algorithm for PIN codes, which makes it easier for attackers to obtain a privileged terminal session by calculating
Sep 22, 20147.223NONO
View all 27 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products27 CVEs
44%
41%
15%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local5 (18.5%)
Network16 (59.3%)
Unknown6 (22.2%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low21 (77.8%)
High0 (0.0%)
Unknown6 (22.2%)
User Interaction
None13 (48.1%)
Unknown6 (22.2%)
Required8 (29.6%)
Privileges Required
Low9 (33.3%)
High1 (3.7%)
None11 (40.7%)
Unknown6 (22.2%)

Exploit Exposure

Signals from CVEs in this vendor scope (27 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Cobham.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Cobham — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Cobham's Products

View all 2 CNAs →

Top CWEs