Usr produces a narrow line of networking and gateway appliances, primarily the G806 and G808 series, with a consistent pattern of hard-coded credential and password vulnerabilities affecting the device firmware. These authentication bypass weaknesses reflect the embedded nature of the product line and represent a durable structural concern for defenders managing these devices. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Usr over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-2645CRITICAL A vulnerability, which was classified as critical, was found in USR USR-G806 1.0.41. Affected is an unknown function of the component Web Management Page. The manipulation of the a | May 11, 2023 | 9.8 | 31 | NO | NO |
CVE-2022-29730CRITICAL USR IOT 4G LTE Industrial Cellular VPN Router v1.0.36 was discovered to contain hard-coded credentials for its highest privileged account. The credentials cannot be altered through | Jun 2, 2022 | 9.8 | 30 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Usr.
Media articles that mention a CVE ID that affects a product developed by Usr — matched by CVE ID, not by vendor name.