Swisscom's vulnerability profile concentrates in consumer and small-business network appliances, particularly its Internet Box and Centro Grande product families, which serve as residential gateways and telecommunications equipment. The recurring weakness classes—including uncontrolled search-path elements, cleartext transmission of sensitive data, input-validation flaws, cross-site scripting, and OS command injection—reflect the embedded firmware and web-management interfaces typical of deployed network devices. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Swisscom over time
Signals from CVEs in this vendor scope (9 CVEs).
9 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-16134HIGH An issue was discovered on Swisscom Internet Box 2, Internet Box Standard, Internet Box Plus prior to 10.04.38, Internet Box 3 prior to 11.01.20, and Internet Box light prior to 08 | Aug 4, 2020 | 8.0 | 25 | NO | NO |
CVE-2019-19940HIGH Incorrect input sanitation in text-oriented user interfaces (telnet, ssh) in Swisscom Centro Grande before 6.16.12 allows remote authenticated users to execute arbitrary commands v | Mar 16, 2020 | 7.2 | 24 | NO | NO |
CVE-2019-19942HIGH Missing output sanitation in Swisscom Centro Grande Centro Grande before 6.16.12, Centro Business 1.0 (ADB) before 7.10.18, and Centro Business 2.0 before 8.02.04 allows a remote a | Mar 16, 2020 | 7.5 | 23 | NO | NO |
CVE-2018-16596HIGH A stack-based buffer overflow in the LAN UPnP service running on UDP port 1900 of Swisscom Internet-Box (2, Standard, and Plus) prior to v09.04.00 and Internet-Box light prior to v | Dec 17, 2018 | 7.5 | 23 | NO | NO |
CVE-2018-6766HIGH Swisscom TVMediaHelper 1.1.0.50 contains a vulnerability that could allow an unauthenticated, remote attacker to execute arbitrary code on the targeted system. This vulnerability e | Mar 27, 2018 | 7.8 | 23 | NO | NO |
CVE-2018-16225MEDIUM The QBee MultiSensor Camera through 4.16.4 accepts unencrypted network traffic from clients (such as the QBee Cam application through 1.0.5 for Android and the Swisscom Home applic | Sep 18, 2018 | 6.5 | 22 | NO | NO |
CVE-2018-6765HIGH Swisscom MySwisscomAssistant 2.17.1.1065 contains a vulnerability that could allow an unauthenticated, remote attacker to execute arbitrary code on the targeted system. This vulner | Mar 27, 2018 | 7.8 | 22 | NO | NO |
CVE-2015-1188HIGH The certificate verification functions in the HNDS service in Swisscom Centro Grande (ADB) DSL routers with firmware before 6.14.00 allows remote attackers to access the management | May 20, 2015 | 7.5 | 21 | NO | NO |
CVE-2019-19941MEDIUM Missing hostname validation in Swisscom Centro Grande before 6.16.12 allows a remote attacker to inject its local IP address as a domain entry in the DNS service of the router via | Mar 16, 2020 | 5.4 | 19 | NO | NO |
Signals from CVEs in this vendor scope (9 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Swisscom.
Media articles that mention a CVE ID that affects a product developed by Swisscom — matched by CVE ID, not by vendor name.