Compal's disclosures concentrate in a narrow portfolio of cable modem and residential gateway devices, such as the CH7465LG and related firmware variants, where the recurring weaknesses center on input-validation and access-control issues endemic to firmware: OS command injection, buffer overflows, path traversal, and improper resource boundary crossing. These are characteristic flaws in network appliances where parsing demands and privilege separation place strain on embedded codebases. Live severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Compal over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-19494HIGH Broadcom based cable modems across multiple vendors are vulnerable to a buffer overflow, which allows a remote attacker to execute arbitrary code at the kernel level via JavaScript | Jan 9, 2020 | 8.8 | 53 | NO | YES |
CVE-2019-13025CRITICAL Compal CH7465LG CH7465LG-NCIP-6.12.18.24-5p8-NOSH devices have Incorrect Access Control because of Improper Input Validation. The attacker can send a maliciously modified POST (HTT | Oct 2, 2019 | 9.8 | 31 | NO | NO |
CVE-2019-17499HIGH The setter.xml component of the Common Gateway Interface on Compal CH7465LG 6.12.18.25-2p4 devices does not properly validate ping command arguments, which allows remote authentica | Oct 11, 2019 | 8.8 | 28 | NO | NO |
CVE-2019-17224MEDIUM The web interface of the Compal Broadband CH7465LG modem (version CH7465LG-NCIP-6.12.18.25-2p6-NOSH) is vulnerable to a /%2f/ path traversal attack, which can be exploited in order | Oct 28, 2019 | 5.3 | 19 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Compal.
Media articles that mention a CVE ID that affects a product developed by Compal — matched by CVE ID, not by vendor name.