Starry's vulnerability footprint is concentrated in its S00111 router product and associated firmware, representing a focused networking-device manufacturer. The durable signal centers on improper cryptographic practices, reflecting the authentication and encryption demands inherent to residential and small-business connectivity appliances. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Starry over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2017-13717HIGH Starry Station (aka Starry Router) sets the Access-Control-Allow-Origin header to "*". This allows any hosted file on any domain to make calls to the device's webserver and brute f | Jun 10, 2019 | 8.8 | 28 | NO | NO |
CVE-2017-13718HIGH The HTTP API supported by Starry Station (aka Starry Router) allows brute forcing the PIN setup by the user on the device, and this allows an attacker to change the Wi-Fi settings | Jun 10, 2019 | 8.0 | 21 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Starry.
Media articles that mention a CVE ID that affects a product developed by Starry — matched by CVE ID, not by vendor name.