Telus's disclosed vulnerabilities center on a narrow range of residential networking and telecommunications equipment, including modem-router devices such as the Actiontec T2200H and related Telus-branded variants. The recurring exposure reflects OS command-injection weaknesses in device firmware, a characteristic flaw class in embedded network appliances where command-line interfaces or management features may be exposed to untrusted input. Live severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Telus over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-20122HIGH The Telus Wi-Fi Hub (PRV65B444A-S-TS) with firmware version 3.00.20 is affected by an authenticated command injection vulnerability in multiple parameters passed to tr69_cmd.cgi. A | Oct 11, 2021 | 7.2 | 27 | NO | NO |
CVE-2018-15553HIGH fileshare.cmd on Telus Actiontec T2200H T2200H-31.128L.03 devices allows OS Command Injection via shell metacharacters in the smbdUserid or smbdPasswd field. | Aug 20, 2018 | 8.8 | 27 | NO | NO |
CVE-2021-20121MEDIUM The Telus Wi-Fi Hub (PRV65B444A-S-TS) with firmware version 3.00.20 is vulnerable to an authenticated arbitrary file read. An authenticated user with physical access to the device | Oct 11, 2021 | 4.0 | 17 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Telus.
Media articles that mention a CVE ID that affects a product developed by Telus — matched by CVE ID, not by vendor name.