Utstarcom's vulnerability footprint centers on a narrow set of consumer and small-business VoIP and wireless networking devices, including the F1000 Wi-Fi phone and BAS storage product line. The observed exposure reflects application-layer hardening challenges, notably the use of hard-coded credentials in device firmware and configuration, which is characteristic of embedded consumer hardware from this era. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Utstarcom over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2005-3718HIGH UTStarcom F1000 VOIP WIFI Phone s2.0 running VxWorks 5.5.1 with kernel WIND 2.6 does not allow users to disable access to (1) SNMP or (2) the rlogin port TCP 513, which allows remo | Nov 21, 2005 | 7.5 | 20 | NO | NO |
CVE-2005-3716HIGH The SNMP daemon in UTStarcom F1000 VOIP WIFI Phone s2.0 running VxWorks 5.5.1 with kernel WIND 2.6 has hard-coded public credentials that cannot be changed, which allows attackers | Nov 21, 2005 | 7.5 | 19 | NO | NO |
CVE-2005-3717HIGH The telnet daemon in UTStarcom F1000 VOIP WIFI Phone s2.0 running VxWorks 5.5.1 with kernel WIND 2.6 has a default username "target" and password "password", which allows remote at | Nov 21, 2005 | 7.5 | 19 | NO | NO |
CVE-2002-1936HIGH UTStarcom BAS 1000 3.1.10 creates several default or back door accounts and passwords, which allows remote attackers to gain access via (1) field account with a password of "*field | Dec 31, 2002 | 7.5 | 19 | NO | NO |
CVE-2005-0745MEDIUM UTStarcom iAN-02EX VoIP Analog Terminal Adaptor (ATA) allows local users to bypass ATA access restrictions by dialing "*#26845#" and causing a device reset. | Mar 9, 2005 | 4.6 | 14 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Utstarcom.
Media articles that mention a CVE ID that affects a product developed by Utstarcom — matched by CVE ID, not by vendor name.