Etictelecom's vulnerability footprint centers on remote-access server appliances and their firmware, a modestly represented product line that carries outsized risk due to the sensitive network-perimeter role these devices occupy. Vulnerabilities affecting the vendor skew toward serious outcomes, with an elevated share reaching critical severity, and recur through weakness classes including cross-site scripting, cleartext transmission, cross-site request forgery, path traversal, and insecure defaults—a pattern characteristic of web-facing administrative interfaces and firmware-configuration layers that require hardened input validation and encryption. Defenders should treat firmware updates for these appliances as high-priority security items given their exposure to remote exploitation; current severity and exploitation activity are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Etictelecom over time
Signals from CVEs in this vendor scope (9 CVEs).
9 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-40981CRITICAL All versions of ETIC Telecom Remote Access Server (RAS) 4.5.0 and prior is vulnerable to malicious file upload. An attacker could take advantage of this to store malicious files on | Nov 10, 2022 | 10.0 | 31 | NO | NO |
CVE-2022-3703CRITICAL All versions of ETIC Telecom Remote Access Server (RAS) 4.5.0 and prior’s web portal is vulnerable to accepting malicious firmware packages that could provide a backdoor to an atta | Nov 10, 2022 | 10.0 | 31 | NO | NO |
CVE-2022-41607HIGH All versions of ETIC Telecom Remote Access Server (RAS) 4.5.0 and prior’s application programmable interface (API) is vulnerable to directory traversal through several different me | Nov 10, 2022 | 7.5 | 25 | NO | NO |
CVE-2024-26155HIGH All versions of ETIC Telecom Remote Access Server (RAS) prior to 4.5.0
expose clear text credentials in the web portal. An attacker can access
the ETIC RAS web portal and view th | Jan 17, 2025 | 8.6 | 23 | NO | NO |
CVE-2024-26153HIGH All versions of ETIC Telecom Remote Access Server (RAS) prior to 4.9.19
are vulnerable to cross-site request forgery (CSRF). An external
attacker with no access to the device can | Jan 17, 2025 | 7.4 | 22 | NO | NO |
CVE-2023-3453HIGH
ETIC Telecom RAS versions 4.7.0 and prior the web management portal authentication disabled by default. This could allow an attacker with adjacent network access to alter the conf | Aug 23, 2023 | 8.1 | 21 | NO | NO |
CVE-2024-26156MEDIUM All versions of ETIC Telecom Remote Access Server (RAS) prior to 4.5.0
are vulnerable to reflected cross site scripting (XSS) attacks in the
method parameter. The ETIC RAS web se | Jan 17, 2025 | 6.1 | 19 | NO | NO |
CVE-2024-26154MEDIUM All versions of ETIC Telecom Remote Access Server (RAS) prior to 4.5.0
are vulnerable to reflected cross site scripting in the appliance site
name. The ETIC RAS web server saves | Jan 17, 2025 | 6.1 | 19 | NO | NO |
CVE-2024-26157MEDIUM All versions of ETIC Telecom Remote Access Server (RAS) prior to 4.5.0
are vulnerable to reflected cross site scripting (XSS) attacks in get
view method under view parameter. The | Jan 17, 2025 | 6.1 | 18 | NO | NO |
Signals from CVEs in this vendor scope (9 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Etictelecom.
Media articles that mention a CVE ID that affects a product developed by Etictelecom — matched by CVE ID, not by vendor name.