Cobham manufactures maritime communication and satellite systems for the shipping and emergency-response sectors, with vulnerabilities concentrating in its VSAT and emergency-beacon product lines such as the Sailor 600 and Explorer 710 series. The vendor's disclosures skew toward serious outcomes, with a meaningful share reaching critical severity, and reflect the authentication and access-control demands of networked maritime appliances exposed to the open ocean and remote provisioning. Recurring weakness classes include cross-site scripting, sensitive-information exposure, improper access control, and authentication bypass, characteristics typical of web-facing device management interfaces that often ship with default credentials or weak input validation. Defenders managing maritime vessel communication systems should inventory affected terminals and prioritize firmware updates to these communication-critical platforms. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Cobham over time
Signals from CVEs in this vendor scope (27 CVEs).
27 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-5267CRITICAL Cobham Sea Tel 121 build 222701 devices allow remote attackers to bypass authentication via a direct request to MenuDealerGx.html, MenuDealer.html, MenuEuNCGx.html, MenuEuNC.html, | Jan 8, 2018 | 9.8 | 31 | NO | NO |
CVE-2019-9531CRITICAL The web application portal of the Cobham EXPLORER 710, firmware version 1.07, allows unauthenticated access to port 5454. This could allow an unauthenticated, remote attacker to co | Oct 10, 2019 | 9.8 | 30 | NO | NO |
CVE-2018-19392CRITICAL Cobham Satcom Sailor 250 and 500 devices before 1.25 contained an unauthenticated password reset vulnerability. This could allow modification of any user account's password (includ | Mar 15, 2019 | 9.8 | 29 | NO | NO |
CVE-2014-2940HIGH Cobham Sailor 900 and 6000 satellite terminals with firmware 1.08 MFHF and 2.11 VHF have hardcoded credentials for the administrator account, which allows attackers to obtain admin | Aug 15, 2014 | 10.0 | 25 | NO | NO |
CVE-2019-9533CRITICAL The root password of the Cobham EXPLORER 710 is the same for all versions of firmware up to and including v1.08. This could allow an attacker to reverse-engineer the password from | Oct 10, 2019 | 9.8 | 24 | NO | NO |
CVE-2018-19393HIGH Cobham Satcom Sailor 800 and 900 devices contained a vulnerability that allowed for arbitrary writing of content to the system's configuration file. This was exploitable via multip | Mar 15, 2019 | 7.5 | 24 | NO | NO |
CVE-2014-0328HIGH The thraneLINK protocol implementation on Cobham devices does not verify firmware signatures, which allows attackers to execute arbitrary code by leveraging physical access or term | Aug 15, 2014 | 9.3 | 24 | NO | NO |
CVE-2013-7180HIGH Cobham SAILOR 900 VSAT; SAILOR FleetBroadBand 150, 250, and 500; EXPLORER BGAN; and AVIATOR 200, 300, 350, and 700D devices do not properly restrict password recovery, which allows | Aug 15, 2014 | 7.8 | 24 | NO | NO |
CVE-2018-5266HIGH Cobham Sea Tel 121 build 222701 devices allow remote attackers to obtain potentially sensitive information about valid usernames by reading the loginName lines at the js/userLogin. | Jan 8, 2018 | 7.5 | 23 | NO | NO |
CVE-2014-2942HIGH Cobham Aviator 700D and 700E satellite terminals use an improper algorithm for PIN codes, which makes it easier for attackers to obtain a privileged terminal session by calculating | Sep 22, 2014 | 7.2 | 23 | NO | NO |
Signals from CVEs in this vendor scope (27 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Cobham.
Media articles that mention a CVE ID that affects a product developed by Cobham — matched by CVE ID, not by vendor name.