Vonage's vulnerability profile concentrates in a small line of residential and small-business phone adapter and gateway products, which bridge legacy telephony infrastructure to modern IP networks. The recurring exposure centers on authentication-bypass conditions, input-handling flaws including cross-site scripting, and memory-safety issues in firmware, reflecting the constraints of embedded communications devices that often operate with minimal update cycles. Live severity, exploitation, and product-specific exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Vonage over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2017-16902HIGH On the Vonage VDV-23 115 3.2.11-0.9.40 home router, sending a long string of characters in the loginPassword and/or loginUsername field to goform/login causes the router to reboot. | Nov 20, 2017 | 7.5 | 38 | NO | YES |
CVE-2017-16843MEDIUM Vonage VDV-23 115 3.2.11-0.9.40 devices have stored XSS via the NewKeyword or NewDomain field to /goform/RgParentalBasic. | Nov 16, 2017 | 5.4 | 29 | NO | YES |
CVE-2007-5791HIGH The Vonage Motorola Phone Adapter VT 2142-VD does not properly verify that a SIP INVITE message originated from a legitimate server, which allows remote attackers to send spoofed I | Nov 1, 2007 | 10.0 | 28 | NO | NO |
CVE-2007-3047HIGH The Vonage VoIP Telephone Adapter has a default administrator username "user" and password "user," which allows remote attackers to obtain administrative access. | Jun 5, 2007 | 10.0 | 25 | NO | NO |
CVE-2023-47304HIGH An issue was discovered in Vonage Box Telephone Adapter VDV23 version VDV21-3.2.11-0.5.1, allows local attackers to bypass UART authentication controls and read/write arbitrary val | Dec 5, 2023 | 7.8 | 21 | NO | NO |
CVE-2007-5792HIGH The Vonage Motorola Phone Adapter VT 2142-VD does not encrypt RTP packets, which might allow remote attackers to eavesdrop by sniffing the network and reconstructing the RTP sessio | Nov 1, 2007 | 7.1 | 19 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Vonage.
Media articles that mention a CVE ID that affects a product developed by Vonage — matched by CVE ID, not by vendor name.