Hughes' vulnerability profile centers on a focused portfolio of satellite and wireless networking equipment, including the HN7000S and DW7000 product lines and their firmware implementations. The recurring exposures involve authentication and input-handling weaknesses—including authentication bypass, improper authentication, cross-site scripting, and input-validation flaws—that are characteristic of remote-access and management interfaces in network appliances. Vulnerabilities affecting this vendor have a tendency to acquire public exploit code, making patched versions a priority where these devices are deployed or internet-reachable; live severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Hughes over time
Signals from CVEs in this vendor scope (10 CVEs).
10 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2000-0012HIGH Buffer overflow in w3-msql CGI program in miniSQL package allows remote attackers to execute commands. | Dec 27, 1999 | 10.0 | 46 | NO | YES |
CVE-1999-0753HIGH The w3-msql CGI script provided with Mini SQL allows remote attackers to view restricted directories. | Aug 17, 1999 | 7.5 | 30 | NO | YES |
CVE-2016-9497HIGH Hughes high-performance broadband satellite modems, models HN7740S DW7000 HN7000S/SM, is vulnerable to an authentication bypass using an alternate path or channel. By default, port | Jul 13, 2018 | 8.8 | 27 | NO | NO |
CVE-2023-22971MEDIUM Cross Site Scripting (XSS) vulnerability in Hughes Network Systems Router Terminal for HX200 v8.3.1.14, HX90 v6.11.0.5, HX50L v6.10.0.18, HN9460 v8.2.0.48, and HN7000S v6.9.0.37, a | Jan 26, 2023 | 6.1 | 22 | NO | NO |
CVE-2016-9495HIGH Hughes high-performance broadband satellite modems, models HN7740S DW7000 HN7000S/SM, uses hard coded credentials. Access to the device's default telnet port (23) can be obtained t | Jul 13, 2018 | 8.8 | 22 | NO | NO |
CVE-1999-0276HIGH mSQL v2.0.1 and below allows remote execution through a buffer overflow. | Jan 1, 1999 | 7.5 | 20 | NO | NO |
CVE-1999-1260HIGH mSQL (Mini SQL) 2.0.6 allows remote attackers to obtain sensitive server information such as logged users, database names, and server version via the ServerStats query. | Feb 15, 1999 | 7.5 | 19 | NO | NO |
CVE-2016-9496MEDIUM Hughes high-performance broadband satellite modems, models HN7740S DW7000 HN7000S/SM, lacks authentication. An unauthenticated user may send an HTTP GET request to http://[ip]/com/ | Jul 13, 2018 | 6.5 | 17 | NO | NO |
CVE-2016-9494MEDIUM Hughes high-performance broadband satellite modems, models HN7740S DW7000 HN7000S/SM, are potentially vulnerable to improper input validation. The device's advanced status web page | Jul 13, 2018 | 6.5 | 17 | NO | NO |
Hughes Technology Mini SQL 2.0.10 through 2.0.12 allows local users to cause a denial of service by creating a very large array in a table, which causes miniSQL to crash when the t | Dec 26, 2001 | 2.1 | 14 | NO | NO |
Signals from CVEs in this vendor scope (10 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Hughes.
Media articles that mention a CVE ID that affects a product developed by Hughes — matched by CVE ID, not by vendor name.