Comtech's vulnerability profile centers on a narrow range of specialized communications and networking appliances, primarily its Stampede FX line and related products, which serve niche infrastructure and defense applications. The recurring exposure involves OS command injection, access-control weaknesses, and cross-site scripting across firmware and administrative interfaces, reflecting the command-driven and web-exposed nature of embedded network devices. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Comtech over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-67015HIGH Incorrect access control in Comtech EF Data CDM-625 / CDM-625A Advanced Satellite Modem with firmware v2.5.1 allows attackers to change the Administrator password and escalate priv | Dec 26, 2025 | 7.5 | 25 | NO | NO |
CVE-2020-7244HIGH Comtech Stampede FX-1010 7.4.3 devices allow remote authenticated administrators to achieve remote code execution by navigating to the Poll Routes page and entering shell metachara | Jan 20, 2020 | 7.2 | 25 | NO | NO |
CVE-2020-7242HIGH Comtech Stampede FX-1010 7.4.3 devices allow remote authenticated administrators to achieve remote code execution by navigating to the Diagnostics Trace Route page and entering she | Jan 20, 2020 | 7.2 | 25 | NO | NO |
CVE-2020-5179HIGH Comtech Stampede FX-1010 7.4.3 devices allow remote authenticated administrators to execute arbitrary OS commands by navigating to the Diagnostics Ping page and entering shell meta | Jan 2, 2020 | 7.2 | 25 | NO | NO |
CVE-2020-7243HIGH Comtech Stampede FX-1010 7.4.3 devices allow remote authenticated administrators to achieve remote code execution by navigating to the Fetch URL page and entering shell metacharact | Jan 20, 2020 | 7.2 | 24 | NO | NO |
CVE-2019-17667MEDIUM Comtech H8 Heights Remote Gateway 2.5.1 devices allow XSS and HTML injection via the Site Name (aka SiteName) field. | Oct 17, 2019 | 5.4 | 20 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Comtech.
Media articles that mention a CVE ID that affects a product developed by Comtech — matched by CVE ID, not by vendor name.