H610s Firmware
Vendor:
First CVE: Jun 3, 2019 · Active for 7 years
62
Total CVEs
More Total CVEs than 99% of tracked products
10.3
Avg CVEs / Year
Higher CVE frequency than 97% of tracked products
6.7
Avg CVSS
Higher Avg CVSS than 37% of tracked products
4.8%
KEV Rate
Higher KEV Rate than 98% of tracked products
Trends Over Time
The number and severity of CVEs published that impact H610s Firmware over time
Volume of CVEsAvg CVSS Base Score
First CVE
Jun 3, 2019
7 years ago
Most Recent CVE
Feb 5, 2025
538 days ago
CVE Severity & Scoring
H610s Firmware62 CVEs
44%
48%
All CVEs353,240 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local38 (61.3%)
Network22 (35.5%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network2 (3.2%)
Attack Complexity
Low49 (79.0%)
High13 (21.0%)
Unknown0 (0.0%)
User Interaction
None54 (87.1%)
Unknown0 (0.0%)
Required8 (12.9%)
Privileges Required
Low31 (50.0%)
High5 (8.1%)
None26 (41.9%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (62 CVEs).
62 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-22555HIGH A heap out-of-bounds write affecting Linux since v2.6.19-rc1 was discovered in net/netfilter/x_tables.c. This allows an attacker to gain privileges or cause a DoS (via heap memory | Jul 7, 2021 | 7.8 | 96 | YES | YES |
CVE-2019-13272HIGH In the Linux kernel before 5.1.17, ptrace_link in kernel/ptrace.c mishandles the recording of the credentials of a process that wants to create a ptrace relationship, which allows | Jul 17, 2019 | 7.8 | 93 | YES | YES |
CVE-2019-2215HIGH A use-after-free in binder.c allows an elevation of privilege from an application to the Linux Kernel. No user interaction is required to exploit this vulnerability, however exploi | Oct 11, 2019 | 7.8 | 92 | YES | YES |
CVE-2022-2068HIGH In addition to the c_rehash shell command injection identified in CVE-2022-1292, further circumstances where the c_rehash script does not properly sanitise shell metacharacters to | Jun 21, 2022 | 7.3 | 76 | NO | NO |
CVE-2024-6119HIGH Issue summary: Applications performing certificate name checks (e.g., TLS
clients checking server certificates) may attempt to read an invalid memory
address resulting in abnormal | Sep 3, 2024 | 7.5 | 62 | NO | NO |
CVE-2024-2398HIGH When an application tells libcurl it wants to allow HTTP/2 server push, and the amount of received headers for the push surpasses the maximum allowed limit (1000), libcurl aborts t | Mar 27, 2024 | 8.6 | 46 | NO | NO |
CVE-2022-0995HIGH An out-of-bounds (OOB) memory write flaw was found in the Linux kernel’s watch_queue event notification subsystem. This flaw can overwrite parts of the kernel state, potentially al | Mar 25, 2022 | 7.8 | 39 | NO | YES |
CVE-2019-10126CRITICAL A flaw was found in the Linux kernel. A heap based buffer overflow in mwifiex_uap_parse_tail_ies function in drivers/net/wireless/marvell/mwifiex/ie.c might lead to memory corrupti | Jun 14, 2019 | 9.8 | 34 | NO | NO |
CVE-2020-8835HIGH In the Linux kernel 5.5.0 and newer, the bpf verifier (kernel/bpf/verifier.c) did not properly restrict the register bounds for 32-bit operations, leading to out-of-bounds reads an | Apr 2, 2020 | 7.8 | 31 | NO | NO |
CVE-2019-18805CRITICAL An issue was discovered in net/ipv4/sysctl_net_ipv4.c in the Linux kernel before 5.0.11. There is a net/ipv4/tcp_input.c signed integer overflow in tcp_ack_update_rtt() when usersp | Nov 7, 2019 | 9.8 | 31 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (62 CVEs).
CISA KEV
3 CVEs
4.8% of CVEs· 98th percentile
Metasploit
4 CVEs
6.5% of CVEs· 97th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
3 CVEs
4.8% of CVEs· 86th percentile
Social Chatter
Signals from CVEs in this product scope (62 CVEs).
Media Mentions
Signals from CVEs in this product scope (62 CVEs).
Top CNAs Publishing CVEs For H610s Firmware
Top CWEs
Versions
No cataloged versions.