Comtrend manufactures broadband networking equipment including routers and cable modems such as the AR-5387UN and CM-6300N series, with a focused but widely deployed embedded device footprint. The durable vulnerability signal across these products centers on application-layer input handling and credential management, with observed weakness classes including cross-site scripting, OS command injection, and insufficiently protected credentials that are characteristic of resource-constrained embedded firmware. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Comtrend over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-10173HIGH Comtrend VR-3033 DE11-416SSG-C01_R02.A2pvI042j1.d26m devices have Multiple Authenticated Command Injection vulnerabilities via the ping and traceroute diagnostic pages, as demonstr | Mar 5, 2020 | 8.8 | 75 | NO | YES |
CVE-2018-20388CRITICAL Comtrend CM-6200un 123.447.007 and CM-6300n 123.553mp1.005 devices allow remote attackers to discover credentials via iso.3.6.1.4.1.4491.2.4.1.1.6.1.1.0 and iso.3.6.1.4.1.4491.2.4. | Dec 23, 2018 | 9.8 | 29 | NO | NO |
CVE-2010-0470MEDIUM Cross-site scripting (XSS) vulnerability in scvrtsrv.cmd in Comtrend CT-507IT ADSL Router allows remote attackers to inject arbitrary web script or HTML via the srvName parameter. | Feb 2, 2010 | 4.3 | 22 | NO | YES |
CVE-2018-8062MEDIUM A cross-site scripting (XSS) vulnerability on Comtrend AR-5387un devices with A731-410JAZ-C04_R02.A2pD035g.d23i firmware allows remote attackers to inject arbitrary web script or H | Oct 23, 2020 | 5.4 | 21 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Comtrend.
Media articles that mention a CVE ID that affects a product developed by Comtrend — matched by CVE ID, not by vendor name.