Fastweb's vulnerability profile centers on a narrow set of residential gateway and GPON modem products, including the FastGate and related Askey-manufactured devices, which are widely deployed in ISP subscriber networks. Vulnerabilities affecting these products skew toward critical-severity outcomes and frequently acquire public exploit code, reflecting the internet-facing management interfaces and embedded-firmware attack surface of CPE hardware. The recurring weakness classes—cross-site request forgery, OS command injection, improper authentication, and out-of-bounds writes—are characteristic of firmware-based control planes with limited validation and access controls. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Fastweb over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-6023HIGH Fastweb FASTgate 0.00.47 devices are vulnerable to CSRF, with impacts including Wi-Fi password changing, Guest Wi-Fi activating, etc. | May 11, 2018 | 8.8 | 38 | NO | YES |
CVE-2019-12489CRITICAL An issue was discovered on Fastweb Askey RTV1907VW 0.00.81_FW_200_Askey 2018-10-02 18:08:18 devices. By using the usb_remove service through an HTTP request, it is possible to inje | Nov 26, 2019 | 9.8 | 33 | NO | NO |
CVE-2018-20122CRITICAL The web interface on FASTGate Fastweb devices with firmware through 0.00.47_FW_200_Askey 2017-05-17 (software through 1.0.1b) exposed a CGI binary that is vulnerable to a command i | Feb 21, 2019 | 9.8 | 31 | NO | NO |
CVE-2022-30114HIGH A heap-based buffer overflow in a network service in Fastweb FASTGate MediaAccess FGA2130FWB, firmware version 18.3.n.0482_FW_230_FGA2130, and DGA4131FWB, firmware version up to 18 | May 19, 2023 | 7.5 | 25 | NO | NO |
CVE-2019-18661HIGH Fastweb FASTGate 1.0.1b devices allow partial authentication bypass by changing a certain check_pwd return value from 0 to 1. An attack does not achieve administrative control of a | Nov 2, 2019 | 7.5 | 24 | NO | NO |
CVE-2020-13620HIGH Fastweb FASTGate GPON FGA2130FWB devices through 2020-05-26 allow CSRF via the router administration web panel, leading to an attacker's ability to perform administrative actions s | Nov 24, 2020 | 8.8 | 22 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Fastweb.
Media articles that mention a CVE ID that affects a product developed by Fastweb — matched by CVE ID, not by vendor name.