Sendquick's vulnerability footprint centers on a narrow product line of SMS gateway appliances and their associated firmware, including the Avera and Entera product families. The durable signal reflects application-layer weaknesses recurrent in embedded gateway devices: command injection, sensitive information logging, and missing authorization controls. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Sendquick over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2017-5136HIGH An issue was discovered on SendQuick Entera and Avera devices before 2HF16. The application failed to check the access control of the request which could result in an attacker bein | Feb 5, 2017 | 7.5 | 25 | NO | NO |
CVE-2016-10098CRITICAL An issue was discovered on SendQuick Entera and Avera devices before 2HF16. Multiple Command Injection vulnerabilities allow attackers to execute arbitrary system commands. | Feb 5, 2017 | 9.8 | 25 | NO | NO |
CVE-2017-5137MEDIUM An issue was discovered on SendQuick Entera and Avera devices before 2HF16. An attacker could request and download the SMS logs from an unauthenticated perspective. | Feb 5, 2017 | 6.2 | 21 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Sendquick.
Media articles that mention a CVE ID that affects a product developed by Sendquick — matched by CVE ID, not by vendor name.