Sprint's vulnerability profile reflects a narrow footprint across consumer and enterprise mobile devices and infrastructure, including access points such as the Airave and handsets like the Evo Shift 4G, with observed weaknesses centered on web-facing input handling such as cross-site scripting. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Sprint over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2007-1821HIGH Sprint Nextel Sprint voice mail systems allow remote attackers to retrieve or remove messages, or reconfigure mailboxes, by spoofing Calling Number Identification (CNID, aka Caller | Apr 2, 2007 | 10.0 | 25 | NO | NO |
CVE-2012-2980HIGH The Samsung and HTC onTouchEvent method implementation for Android on the T-Mobile myTouch 3G Slide, HTC Merge, Sprint EVO Shift 4G, HTC ChaCha, AT&T Status, HTC Desire Z, T-Mobile | Aug 21, 2012 | 7.1 | 22 | NO | NO |
CVE-2013-2270MEDIUM Cross-site scripting (XSS) vulnerability in the administration page in Airvana HubBub C1-600-RT and Sprint AIRAVE 2.5 allows remote attackers to inject arbitrary web script or HTML | Mar 9, 2014 | 4.3 | 18 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Sprint.
Media articles that mention a CVE ID that affects a product developed by Sprint — matched by CVE ID, not by vendor name.