Sagemcom's vulnerability footprint concentrates on a modestly sized portfolio of residential and small-business networking devices, particularly its F@ST router and gateway products, which are widely deployed in access-layer networks. Vulnerabilities affecting the vendor skew toward serious outcomes, frequently acquire public exploit code, and recur through firmware-level and application-layer weakness classes including buffer overflows, unsafe deserialization, cross-site scripting, weak entropy, and insufficient session management. Defenders should prioritize inventory and patching of these access-tier devices, particularly in ISP and small-office deployments; live severity and exploitation counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Sagemcom over time
Signals from CVEs in this vendor scope (9 CVEs).
9 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-19494HIGH Broadcom based cable modems across multiple vendors are vulnerable to a buffer overflow, which allows a remote attacker to execute arbitrary code at the kernel level via JavaScript | Jan 9, 2020 | 8.8 | 53 | NO | YES |
CVE-2025-29329CRITICAL Buffer Overflow in the ippprint (Internet Printing Protocol) service in Sagemcom F@st 3686 MAGYAR_4.121.0 allows remote attacker to execute arbitrary code by sending a crafted HTTP | Jan 12, 2026 | 9.8 | 34 | NO | NO |
CVE-2017-6552HIGH Livebox 3 Sagemcom SG30_sip-fr-5.15.8.1 devices have an insufficiently large default value for the maximum IPv6 routing table size: it can be filled within minutes. An attacker can | Mar 9, 2017 | 7.5 | 30 | NO | YES |
CVE-2021-3304CRITICAL Sagemcom F@ST 3686 v2 3.495 devices have a buffer overflow via a long sessionKey to the goform/login URI. | Jan 26, 2021 | 9.8 | 29 | NO | NO |
CVE-2020-24034HIGH Sagemcom F@ST 5280 routers using firmware version 1.150.61 have insecure deserialization that allows any authenticated user to perform a privilege escalation to any other user. By | Sep 1, 2020 | 8.8 | 26 | NO | NO |
CVE-2024-1623HIGH Insufficient session timeout vulnerability in the FAST3686 V2 Vodafone router from Sagemcom. This vulnerability could allow a local attacker to access the administration panel with | Mar 14, 2024 | 7.8 | 23 | NO | NO |
CVE-2020-21733MEDIUM Sagemcom F@ST3686 v1.0 HUN 3.97.0 has XSS via RgDiagnostics.asp, RgDdns.asp, RgFirewallEL.asp, RgVpnL2tpPptp.asp. | Sep 14, 2020 | 6.1 | 23 | NO | NO |
CVE-2019-9555MEDIUM Sagemcom F@st 5260 routers using firmware version 0.4.39, in WPA mode, default to using a PSK that is generated from a 2-part wordlist of known values and a nonce with insufficient | Mar 5, 2019 | 5.3 | 19 | NO | NO |
CVE-2020-29138MEDIUM Incorrect Access Control in the configuration backup path in SAGEMCOM F@ST3486 NET DOCSIS 3.0, software NET_4.109.0, allows remote unauthenticated users to download the router conf | Nov 27, 2020 | 5.3 | 18 | NO | NO |
Signals from CVEs in this vendor scope (9 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Sagemcom.
Media articles that mention a CVE ID that affects a product developed by Sagemcom — matched by CVE ID, not by vendor name.