Remote Access Server Firmware
Vendor:
First CVE: Nov 10, 2022 · Active for 3 years
9
Total CVEs
More Total CVEs than 86% of tracked products
3.0
Avg CVEs / Year
Higher CVE frequency than 76% of tracked products
7.8
Avg CVSS
Higher Avg CVSS than 63% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Remote Access Server Firmware over time
Volume of CVEsAvg CVSS Base Score
First CVE
Nov 10, 2022
3 years ago
Most Recent CVE
Jan 17, 2025
554 days ago
CVE Severity & Scoring
Remote Access Server Firmware9 CVEs
33%
44%
22%
All CVEs352,708 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network8 (88.9%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network1 (11.1%)
Attack Complexity
Low9 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None5 (55.6%)
Unknown0 (0.0%)
Required4 (44.4%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None9 (100.0%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (9 CVEs).
9 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-40981CRITICAL All versions of ETIC Telecom Remote Access Server (RAS) 4.5.0 and prior is vulnerable to malicious file upload. An attacker could take advantage of this to store malicious files on | Nov 10, 2022 | 10.0 | 31 | NO | NO |
CVE-2022-3703CRITICAL All versions of ETIC Telecom Remote Access Server (RAS) 4.5.0 and prior’s web portal is vulnerable to accepting malicious firmware packages that could provide a backdoor to an atta | Nov 10, 2022 | 10.0 | 31 | NO | NO |
CVE-2022-41607HIGH All versions of ETIC Telecom Remote Access Server (RAS) 4.5.0 and prior’s application programmable interface (API) is vulnerable to directory traversal through several different me | Nov 10, 2022 | 7.5 | 25 | NO | NO |
CVE-2024-26155HIGH All versions of ETIC Telecom Remote Access Server (RAS) prior to 4.5.0
expose clear text credentials in the web portal. An attacker can access
the ETIC RAS web portal and view th | Jan 17, 2025 | 8.6 | 23 | NO | NO |
CVE-2024-26153HIGH All versions of ETIC Telecom Remote Access Server (RAS) prior to 4.9.19
are vulnerable to cross-site request forgery (CSRF). An external
attacker with no access to the device can | Jan 17, 2025 | 7.4 | 22 | NO | NO |
CVE-2023-3453HIGH
ETIC Telecom RAS versions 4.7.0 and prior the web management portal authentication disabled by default. This could allow an attacker with adjacent network access to alter the conf | Aug 23, 2023 | 8.1 | 21 | NO | NO |
CVE-2024-26156MEDIUM All versions of ETIC Telecom Remote Access Server (RAS) prior to 4.5.0
are vulnerable to reflected cross site scripting (XSS) attacks in the
method parameter. The ETIC RAS web se | Jan 17, 2025 | 6.1 | 19 | NO | NO |
CVE-2024-26154MEDIUM All versions of ETIC Telecom Remote Access Server (RAS) prior to 4.5.0
are vulnerable to reflected cross site scripting in the appliance site
name. The ETIC RAS web server saves | Jan 17, 2025 | 6.1 | 19 | NO | NO |
CVE-2024-26157MEDIUM All versions of ETIC Telecom Remote Access Server (RAS) prior to 4.5.0
are vulnerable to reflected cross site scripting (XSS) attacks in get
view method under view parameter. The | Jan 17, 2025 | 6.1 | 18 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (9 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (9 CVEs).
Media Mentions
Signals from CVEs in this product scope (9 CVEs).
Top CNAs Publishing CVEs For Remote Access Server Firmware
Top CWEs
Versions
No cataloged versions.