Thomson's vulnerability profile centers on a narrow set of consumer and small-business networking and telecommunications products, including cable modems, routers, and VoIP phones deployed across residential and enterprise edges. The observed weakness classes—primarily web-application input handling issues such as cross-site scripting and request forgery, alongside configuration and authentication gaps—reflect the embedded web-management interfaces typical of these devices. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Thomson over time
Signals from CVEs in this vendor scope (9 CVEs).
9 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2006-0947HIGH Thomson SpeedTouch modem running firmware 5.3.2.6.0 allows remote attackers to create users that cannot be deleted via scripting code in the "31" parameter in a NewUser function, w | Mar 1, 2006 | 7.5 | 29 | NO | YES |
CVE-2005-0494HIGH The RgSecurity form in the HTTP server for the Thomson TCW690 cable modem running firmware 2.1 and software ST42.03.0a does not properly validate the password before performing cha | Feb 21, 2005 | 7.5 | 29 | NO | YES |
CVE-2004-0641HIGH Thomson SpeedTouch 510 ADSL Router with firmware GV8BAA3.270, and possibly earlier versions, generates predictable TCP Initial Sequence Numbers (ISNs), which allows remote attacker | Aug 5, 2004 | 7.5 | 29 | NO | YES |
CVE-2014-4716MEDIUM Cross-site request forgery (CSRF) vulnerability in Thomson TWG87OUIR allows remote attackers to hijack the authentication of unspecified victims for requests that change passwords | Jul 3, 2014 | 6.8 | 27 | NO | YES |
CVE-2007-4553MEDIUM The Thomson ST 2030 SIP phone with software 1.52.1 allows remote attackers to cause a denial of service (device hang) via an INVITE message with a Via header that contains a '/' (s | Aug 28, 2007 | 5.0 | 25 | NO | YES |
CVE-2003-1085MEDIUM The HTTP server in the Thomson TWC305, TWC315, and TCW690 cable modem ST42.03.0a allows remote attackers to cause a denial of service (unstable service) via a long GET request, pos | Dec 31, 2003 | 5.0 | 24 | NO | YES |
CVE-2007-6003MEDIUM Cross-site scripting (XSS) vulnerability in cgi/b/ic/connect in the Thomson SpeedTouch 716 with firmware 5.4.0.14 allows remote attackers to inject arbitrary web script or HTML via | Nov 15, 2007 | 4.3 | 21 | NO | YES |
CVE-2006-0946MEDIUM Cross-site scripting (XSS) vulnerability in Thomson SpeedTouch modems running firmware 5.3.2.6.0 allows remote attackers to inject arbitrary web script or HTML via the name paramet | Mar 1, 2006 | 4.3 | 21 | NO | YES |
CVE-2007-4753MEDIUM The Thomson ST 2030 SIP phone with software 1.52.1 allows remote attackers to cause a denial of service (device hang) via (1) an empty SIP message or (2) a SIP INVITE message with | Sep 8, 2007 | 5.0 | 15 | NO | NO |
Signals from CVEs in this vendor scope (9 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Thomson.
Media articles that mention a CVE ID that affects a product developed by Thomson — matched by CVE ID, not by vendor name.