Netopia's vulnerability profile centers on a focused line of legacy remote-access and networking products, including Timbuktu Pro and its R-series ISDN routers, which occupy a narrow but historically prominent niche in enterprise connectivity infrastructure. The recurring weakness classes—input validation and path-traversal flaws—reflect the parsing and file-access demands of remote-management and gateway appliances, and public exploit code has been available for vulnerabilities in this product family. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Netopia over time
Signals from CVEs in this vendor scope (11 CVEs).
11 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2008-1117HIGH Directory traversal vulnerability in the Notes (aka Flash Notes or instant messages) feature in tb2ftp.dll in Timbuktu Pro 8.6.5 for Windows, and possibly 8.7 for Mac OS X, allows | Mar 14, 2008 | 10.0 | 79 | NO | YES |
CVE-2008-1118HIGH Timbuktu Pro 8.6.5 for Windows, and possibly 8.7 for Mac OS X, does not perform input validation before logging information fields taken from packets from a remote peer, which allo | Mar 14, 2008 | 7.5 | 29 | NO | YES |
CVE-2000-0142MEDIUM The authentication protocol in Timbuktu Pro 2.0b650 allows remote attackers to cause a denial of service via connections to port 407 and 1417. | Feb 11, 2000 | 5.0 | 25 | NO | YES |
CVE-2002-0135MEDIUM Netopia Timbuktu Pro 6.0.1 and earlier allows remote attackers to cause a denial of service (crash) via a series of connections to one of the ports (1417 - 1420). | Mar 25, 2002 | 5.0 | 23 | NO | YES |
The Netopia R9100 router does not prevent authenticated users from modifying SNMP tables, even if the administrator has configured it to do so. | May 16, 2000 | 3.6 | 20 | NO | YES |
CVE-2008-1337MEDIUM The instant message service in Timbuktu Pro 8.6.5 RC 229 and earlier for Windows allows remote attackers to cause (1) a denial of service (daemon crash) via an invalid Version fiel | Mar 14, 2008 | 5.0 | 18 | NO | NO |
CVE-2004-0810MEDIUM Buffer overflow in Netopia Timbuktu 7.0.3 allows remote attackers to cause a denial of service (server process crash) via a certain data string that is sent to multiple simultaneou | Dec 23, 2004 | 5.0 | 15 | NO | NO |
CVE-2001-0185MEDIUM Netopia R9100 router version 4.6 allows authenticated users to cause a denial of service by using the router's telnet program to connect to the router's IP address, which causes a | Mar 26, 2001 | 5.0 | 15 | NO | NO |
CVE-2000-1179MEDIUM Netopia ISDN Router 650-ST before 4.3.5 allows remote attackers to read system logs without authentication by directly connecting to the login screen and typing certain control cha | Jan 9, 2001 | 5.0 | 15 | NO | NO |
CVE-2000-0086MEDIUM Netopia Timbuktu Pro sends user IDs and passwords in cleartext, which allows remote attackers to obtain them via sniffing. | Jan 18, 2000 | 5.0 | 15 | NO | NO |
Signals from CVEs in this vendor scope (11 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Netopia.
Media articles that mention a CVE ID that affects a product developed by Netopia — matched by CVE ID, not by vendor name.