Foxconn's vulnerability footprint centers on a narrow range of wireless networking and management products, including the AP-FC4064-T access point and its associated firmware and update utilities. The observed weakness classes cluster around input-handling and credential-management issues, including cross-site scripting, hard-coded credentials, and weak password requirements, which are characteristic of embedded network appliances. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Foxconn over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-9112CRITICAL A low privileged admin account with a weak default password of admin exists on the Foxconn FEMTO AP-FC4064-T AP_GT_B38_5.8.3lb15-W47 LTE Build 15. In addition, its web management p | May 10, 2018 | 9.8 | 31 | NO | NO |
CVE-2018-6312HIGH A privileged account with a weak default password on the Foxconn femtocell FEMTO AP-FC4064-T version AP_GT_B38_5.8.3lb15-W47 LTE Build 15 can be used to turn on the TELNET service | Mar 10, 2018 | 7.2 | 24 | NO | NO |
CVE-2018-6311MEDIUM One can gain root access on the Foxconn femtocell FEMTO AP-FC4064-T version AP_GT_B38_5.8.3lb15-W47 LTE Build 15 via UART pins without any restrictions, which leads to full system | Mar 10, 2018 | 6.8 | 23 | NO | NO |
CVE-2020-24088HIGH An issue was discovered in MmMapIoSpace routine in Foxconn Live Update Utility 2.1.6.26, allows local attackers to escalate privileges. | Sep 11, 2023 | 7.8 | 22 | NO | NO |
CVE-2018-9111MEDIUM Cross Site Scripting (XSS) exists on the Foxconn FEMTO AP-FC4064-T AP_GT_B38_5.8.3lb15-W47 LTE Build 15 via the configuration of a user account. An attacker can execute arbitrary s | May 10, 2018 | 5.4 | 20 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Foxconn.
Media articles that mention a CVE ID that affects a product developed by Foxconn — matched by CVE ID, not by vendor name.