Technicolor's vulnerability footprint centers on a moderately broad portfolio of consumer cable modems and related networking equipment—including the Thomson TCW710 and DPC3928SL product lines—that occupy the gateway position in residential broadband deployments. Vulnerabilities affecting the vendor skew strongly toward critical-severity outcomes and frequently acquire public exploit code, reflecting both the internet-facing nature of these devices and their role as a pivot point for downstream network access. The exposure recurs across firmware and hardware variants through weakness classes dominated by input-validation and credentialing issues—chiefly cross-site scripting, insufficient credential protection, and uncontrolled resource consumption—that are characteristic of embedded web-management interfaces with limited memory and processing constraints. Defenders should prioritize patching or isolating affected modem hardware, particularly older or unsupported models, and restrict administrative access to these devices; live exploitation activity and severity counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Technicolor over time
Signals from CVEs in this vendor scope (42 CVEs).
42 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-19494HIGH Broadcom based cable modems across multiple vendors are vulnerable to a buffer overflow, which allows a remote attacker to execute arbitrary code at the kernel level via JavaScript | Jan 9, 2020 | 8.8 | 53 | NO | YES |
CVE-2017-5135CRITICAL Certain Technicolor devices have an SNMP access-control bypass, possibly involving an ISP customization in some cases. The Technicolor (formerly Cisco) DPC3928SL with firmware D392 | Apr 27, 2017 | 9.1 | 52 | NO | YES |
CVE-2019-18396HIGH An issue was discovered in certain Oi third-party firmware that may be installed on Technicolor TD5130v2 devices. A Command Injection in the Ping module in the Web Interface in OI_ | Oct 31, 2019 | 7.2 | 41 | NO | YES |
CVE-2014-1677HIGH Technicolor TC7200 with firmware STD6.01.12 could allow remote attackers to obtain sensitive information. | Apr 3, 2017 | 7.5 | 37 | NO | YES |
CVE-2016-7454HIGH CSRF vulnerability on Technicolor TC dpc3941T (formerly Cisco dpc3941T) devices with firmware dpc3941-P20-18-v303r20421733-160413a-CMCST allows an attacker to change the Wi-Fi pass | Dec 17, 2016 | 8.0 | 37 | NO | YES |
CVE-2014-9144HIGH Technicolor Router TD5130 with firmware 2.05.C29GV allows remote attackers to execute arbitrary commands via shell metacharacters in the ping field (setobject_ip parameter). | Dec 5, 2014 | 7.5 | 32 | NO | YES |
CVE-2019-19495CRITICAL The web interface on the Technicolor TC7230 STEB 01.25 is vulnerable to DNS rebinding, which allows a remote attacker to configure the cable modem via JavaScript in a victim's brow | Jan 8, 2020 | 9.8 | 31 | NO | NO |
CVE-2018-20440CRITICAL Technicolor CWA0101 CWA0101E-A23E-c7000r5712-170315-SKC devices allow remote attackers to discover Wi-Fi credentials via iso.3.6.1.4.1.4413.2.2.2.1.5.4.1.14.1.3.10001 and 1.3.6.1.4 | Dec 25, 2018 | 9.8 | 31 | NO | NO |
CVE-2014-0621MEDIUM Multiple cross-site request forgery (CSRF) vulnerabilities in Technicolor (formerly Thomson) TC7200 STD6.01.12 allow remote attackers to hijack the authentication of administrators | Jan 8, 2014 | 6.8 | 31 | NO | YES |
CVE-2017-14127CRITICAL Command Injection in the Ping Module in the Web Interface on Technicolor TD5336 OI_Fw_v7 devices allows remote attackers to execute arbitrary OS commands as root via shell metachar | Sep 4, 2017 | 9.8 | 30 | NO | NO |
Signals from CVEs in this vendor scope (42 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Technicolor.
Media articles that mention a CVE ID that affects a product developed by Technicolor — matched by CVE ID, not by vendor name.