Verizon's vulnerability profile centers on a narrow portfolio of wireless networking and outdoor communication equipment, including LTE small-cell units and network extenders that serve as critical infrastructure in carrier deployments. Vulnerabilities affecting these products skew toward serious outcomes, with a meaningful share reaching critical severity, and recur through authentication-adjacent weakness classes including improper authentication, OS command injection, unrestricted file uploads, weak password enforcement, and authentication bypass via capture-replay attacks. The concentration of these flaws in firmware and access-control boundaries reflects the embedded nature of the hardware and the high-value nature of carrier-grade network gear, where authentication circumvention can enable unauthorized network access or service disruption. Defenders managing these device types should prioritize firmware updates and restrict administrative exposure; current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Verizon over time
Signals from CVEs in this vendor scope (20 CVEs).
20 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-3914HIGH Remote command injection vulnerability in Verizon Fios Quantum Gateway (G1100) firmware version 02.01.00.05 allows a remote, authenticated attacker to execute arbitrary commands on | Apr 11, 2019 | 7.2 | 40 | NO | NO |
CVE-2013-0126MEDIUM Multiple cross-site request forgery (CSRF) vulnerabilities in index.cgi on the Verizon FIOS Actiontec MI424WR-GEN3I router with firmware 40.19.36 allow remote attackers to hijack t | Mar 21, 2013 | 6.8 | 32 | NO | YES |
CVE-2022-28375CRITICAL Verizon 5G Home LVSKIHP OutDoorUnit (ODU) 3.33.101.0 does not property sanitize user-controlled parameters within the crtcswitchsimprofile function of the crtcrpc JSON listener. A | Jul 14, 2022 | 9.8 | 31 | NO | NO |
CVE-2022-28373CRITICAL Verizon 5G Home LVSKIHP InDoorUnit (IDU) 3.4.66.162 does not properly sanitize user-controlled parameters within the crtcreadpartition function of the crtcrpc JSON listener in /usr | Jul 14, 2022 | 9.8 | 30 | NO | NO |
CVE-2022-28369CRITICAL Verizon 5G Home LVSKIHP InDoorUnit (IDU) 3.4.66.162 does not validate the user-provided URL within the crtcmode function's enable_ssh sub-operation of the crtcrpc JSON listener (fo | Jul 14, 2022 | 9.8 | 30 | NO | NO |
CVE-2022-28374HIGH Verizon 5G Home LVSKIHP OutDoorUnit (ODU) 3.33.101.0 does not property sanitize user-controlled parameters within the DMACC URLs on the Settings page of the Engineering portal. An | Jul 14, 2022 | 8.8 | 28 | NO | NO |
CVE-2022-28376HIGH Verizon 5G Home LVSKIHP outside devices through 2022-02-15 allow anyone (knowing the device's serial number) to access a CPE admin website, e.g., at the 10.0.0.1 IP address. The pa | Apr 3, 2022 | 8.1 | 27 | NO | NO |
CVE-2020-7660HIGH serialize-javascript prior to 3.1.0 allows remote attackers to inject arbitrary code via the function "deleteFunctions" within "index.js". | Jun 1, 2020 | 8.1 | 27 | NO | NO |
CVE-2019-3916HIGH Information disclosure vulnerability in Verizon Fios Quantum Gateway (G1100) firmware version 02.01.00.05 allows an remote, unauthenticated attacker to retrieve the value of the pa | Apr 11, 2019 | 7.5 | 26 | NO | NO |
CVE-2022-28377HIGH On Verizon 5G Home LVSKIHP InDoorUnit (IDU) 3.4.66.162 and OutDoorUnit (ODU) 3.33.101.0 devices, the CRTC and ODU RPC endpoints rely on a static account username/password for acces | Jul 14, 2022 | 7.5 | 25 | NO | NO |
Signals from CVEs in this vendor scope (20 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Verizon.
Media articles that mention a CVE ID that affects a product developed by Verizon — matched by CVE ID, not by vendor name.