Comba develops wireless networking and access-point products, with vulnerabilities observed primarily in its AC2400 and AP2600 device lines and their firmware. The recurring weakness classes—insufficiently protected credentials, missing authentication for critical functions, missing encryption of sensitive data, and use of broken cryptographic algorithms—reflect the authentication and confidentiality challenges common to embedded networking devices. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Comba over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-15654HIGH Comba AC2400 devices are prone to password disclosure via a simple crafted /09/business/upgrade/upcfgAction.php?download=true request to the web management server. The request does | Mar 19, 2020 | 7.5 | 24 | NO | NO |
CVE-2019-15653HIGH Comba AP2600-I devices through A02,0202N00PD2 are prone to password disclosure via an insecure authentication mechanism. The HTML source code of the login page contains values that | Mar 19, 2020 | 7.5 | 23 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Comba.
Media articles that mention a CVE ID that affects a product developed by Comba — matched by CVE ID, not by vendor name.