Ericsson recognizes the importance of security and privacy, and we take security issues very seriously. We are committed to communicating and working in a timely manner for any reported security vulnerability, whether from an employee, customer, partner, or other outside party.
October 9, 2023
This notice is a response to the publication “Rooting the Cradlepoint IBR600” that was published in October 2023. Cradlepoint is aware of the issue and has…
May 25, 2023
Cradlepoint is aware of and has evaluated this issue.
November 18, 2022
An authenticated local user on NetCloud OS (NCOS) versions before 7.22.70 can run a restricted shell escape sequence utilizing an OpenVPN Tunnel Feature…
November 3, 2022
Cradlepoint became aware of the potential for information not intended to be included in activity logs or to have been written to the logs on Cradlepoint…
April 14, 2022
Public Disclosure: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-22963
December 20, 2021
A critical vulnerability for Log4J was publicly disclosed on Dec. 10, 2021. The Cradlepoint incident response team investigated, identified and patched…
November 8, 2021
An authenticated user on NetCloud OS (NCOS) versions before 7.21.80 can run restricted shell escape sequences that provide the authenticated user the…
June 22, 2021
Cradlepoint Secure Threat Management (CPSTM) leverages Trend Micro’s Deep Packet Inspection (DPI) solution and is affected by publicly disclosed privilege…
May 28, 2021
Public Disclosure: https://kb.cert.org/vuls/id/799380
May 21, 2021
Public Disclosure: https://www.fragattacks.com/
January 19, 2021
Public Disclosure: https://www.jsof-tech.com/disclosures/dnspooq/
June 17, 2020
Cradlepoint does not use a version of UPnP that is vulnerable to CVE-2020-12695 (aka CallStranger ). CallStranger takes advantage of a Callback header value…
August 6, 2019
The device permitted enabling of the “cproot” account through the “Add User” functionality built in to the administrative interfaces.
January 18, 2019
NetCloud Manager (NCM) system administrator was been changed without notifying the client system administrator. A defect was released to production that…
October 20, 2018
This vulnerability applied to customers who did not changed their default passwords. If passwords were changed from the default, this vulnerability will…
October 20, 2018
This vulnerability applied to customers who have not changed their default passwords. If the default password was changed, this vulnerability has a minimal…