Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Netopia

First CVE: Jan 18, 2000Active for: 27 yearsTotal CVEs: 11
31.6
VTI Score
Medium

Netopia's vulnerability profile centers on a focused line of legacy remote-access and networking products, including Timbuktu Pro and its R-series ISDN routers, which occupy a narrow but historically prominent niche in enterprise connectivity infrastructure. The recurring weakness classes—input validation and path-traversal flaws—reflect the parsing and file-access demands of remote-management and gateway appliances, and public exploit code has been available for vulnerabilities in this product family. Current severity, exploitation activity, and exposure counts are shown alongside this summary.

FAUCET AI Generated
11
Total CVEs
More Total CVEs than 92% of tracked vendors
0.4
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 4% of tracked vendors
5.3
Avg CVSS Score
Higher Avg CVSS Score than 15% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Netopia over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jan 18, 2000
26 years ago
Most Recent CVE
Mar 14, 2008
6,706 days ago

Products(6 total)

Top CVEs

Signals from CVEs in this vendor scope (11 CVEs).

11 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2008-1117HIGH
Directory traversal vulnerability in the Notes (aka Flash Notes or instant messages) feature in tb2ftp.dll in Timbuktu Pro 8.6.5 for Windows, and possibly 8.7 for Mac OS X, allows
Mar 14, 200810.079NOYES
CVE-2008-1118HIGH
Timbuktu Pro 8.6.5 for Windows, and possibly 8.7 for Mac OS X, does not perform input validation before logging information fields taken from packets from a remote peer, which allo
Mar 14, 20087.529NOYES
CVE-2000-0142MEDIUM
The authentication protocol in Timbuktu Pro 2.0b650 allows remote attackers to cause a denial of service via connections to port 407 and 1417.
Feb 11, 20005.025NOYES
CVE-2002-0135MEDIUM
Netopia Timbuktu Pro 6.0.1 and earlier allows remote attackers to cause a denial of service (crash) via a series of connections to one of the ports (1417 - 1420).
Mar 25, 20025.023NOYES
CVE-2000-0379LOW
The Netopia R9100 router does not prevent authenticated users from modifying SNMP tables, even if the administrator has configured it to do so.
May 16, 20003.620NOYES
CVE-2008-1337MEDIUM
The instant message service in Timbuktu Pro 8.6.5 RC 229 and earlier for Windows allows remote attackers to cause (1) a denial of service (daemon crash) via an invalid Version fiel
Mar 14, 20085.018NONO
CVE-2004-0810MEDIUM
Buffer overflow in Netopia Timbuktu 7.0.3 allows remote attackers to cause a denial of service (server process crash) via a certain data string that is sent to multiple simultaneou
Dec 23, 20045.015NONO
CVE-2001-0185MEDIUM
Netopia R9100 router version 4.6 allows authenticated users to cause a denial of service by using the router's telnet program to connect to the router's IP address, which causes a
Mar 26, 20015.015NONO
CVE-2000-1179MEDIUM
Netopia ISDN Router 650-ST before 4.3.5 allows remote attackers to read system logs without authentication by directly connecting to the login screen and typing certain control cha
Jan 9, 20015.015NONO
CVE-2000-0086MEDIUM
Netopia Timbuktu Pro sends user IDs and passwords in cleartext, which allows remote attackers to obtain them via sniffing.
Jan 18, 20005.015NONO
View all 11 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products11 CVEs
18%
64%
18%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
LowMediumHigh
Attack Vector
Local0 (0.0%)
Network0 (0.0%)
Unknown11 (100.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low0 (0.0%)
High0 (0.0%)
Unknown11 (100.0%)
User Interaction
None0 (0.0%)
Unknown11 (100.0%)
Required0 (0.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None0 (0.0%)
Unknown11 (100.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (11 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
1 CVE
9.1% of CVEs· 98th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
5 CVEs
45.5% of CVEs· 81st percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Netopia.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Netopia — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Netopia's Products

View all 1 CNAs →

Top CWEs