Exfo manufactures telecommunications test and measurement equipment, with its vulnerability footprint concentrated in the BV-10 optical service platform and related firmware. The durable signal centers on authentication and credential-management weaknesses—including improper authentication, hard-coded credentials, and incorrect permission assignment—reflecting the administrative access controls critical to networked test equipment. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Exfo over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-39185CRITICAL EXFO - BV-10 Performance Endpoint Unit Undocumented privileged user. Unit has an undocumented hard-coded privileged user. | Jan 12, 2023 | 9.8 | 30 | NO | NO |
CVE-2022-39184CRITICAL EXFO - BV-10 Performance Endpoint Unit authentication bypass User can manually manipulate access enabling authentication bypass. | Jan 12, 2023 | 9.8 | 30 | NO | NO |
CVE-2022-39186MEDIUM EXFO - BV-10 Performance Endpoint Unit misconfiguration. System configuration file has misconfigured permissions | Jan 12, 2023 | 5.5 | 20 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Exfo.
Media articles that mention a CVE ID that affects a product developed by Exfo — matched by CVE ID, not by vendor name.