Security alerts

Ericsson recognizes the importance of security and privacy, and we take security issues very seriously. We are committed to communicating and working in a timely manner for any reported security vulnerability, whether from an employee, customer, partner, or other outside party.

Submit a security issue

Security Bulletin – 2023-001: Possibility to Replace Endpoint Operating System

October 9, 2023

This notice is a response to the publication “Rooting the Cradlepoint IBR600” that was published in October 2023. Cradlepoint is aware of the issue and has…


CVE-2022-47522: WiFi Framing Frames Vulnerability

May 25, 2023

Cradlepoint is aware of and has evaluated this issue.


CVE-2022-3086: Cradlepoint NCOS Command Injection

November 18, 2022

An authenticated local user on NetCloud OS (NCOS) versions before 7.22.70 can run a restricted shell escape sequence utilizing an OpenVPN Tunnel Feature…


Security Bulletin – 2022-001: Activity Log Secrets Non-Public Information

November 3, 2022

Cradlepoint became aware of the potential for information not intended to be included in activity logs or to have been written to the logs on Cradlepoint…


CVE-2022-22963: Remote code execution in Spring Cloud Function by malicious Spring Expression

April 14, 2022

Public Disclosure: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-22963


CVE-2021-44228/CVE-2021-45046/CVE-2021-45105: Apache Log4j Security Vulnerabilities Update

December 20, 2021

A critical vulnerability for Log4J was publicly disclosed on Dec. 10, 2021. The Cradlepoint incident response team investigated, identified and patched…


CVE-2021-37471: Denial of Console Availability Using Restricted Shell Escape Sequences

November 8, 2021

An authenticated user on NetCloud OS (NCOS) versions before 7.21.80 can run restricted shell escape sequences that provide the authenticated user the…


CPSEC-496: Cradlepoint Secure Threat Management (CPSTM) Vulnerable to Trend Micro Network Security Vulnerabilities

June 22, 2021

Cradlepoint Secure Threat Management (CPSTM) leverages Trend Micro’s Deep Packet Inspection (DPI) solution and is affected by publicly disclosed privilege…


CPSEC-425 Vulnerability Alert

May 28, 2021

Public Disclosure: https://kb.cert.org/vuls/id/799380


CPSEC-486: Cradlepoint Wi-Fi Enabled Hardware Vulnerable to FragAttack (Wi-Fi Packet Fragmentation Vulnerabilities)

May 21, 2021

Public Disclosure: https://www.fragattacks.com/


CPSEC-368: NetCloud OS (NCOS) Vulnerable to DNSpooq (DNSmasq)

January 19, 2021

Public Disclosure: https://www.jsof-tech.com/disclosures/dnspooq/


CPSEC-278: Cradlepoint Not Vulnerable to CVE-2020-12695 (aka CallStranger)

June 17, 2020

Cradlepoint does not use a version of UPnP that is vulnerable to CVE-2020-12695 (aka CallStranger ). CallStranger takes advantage of a Callback header value…


CPSEC-49: Tech Support Mode Warning Bypass

August 6, 2019

The device permitted enabling of the “cproot” account through the “Add User” functionality built in to the administrative interfaces.


CPSEC-20: NCM Account Automation assigns System Admin role to users on POD

January 18, 2019

NetCloud Manager (NCM) system administrator was been changed without notifying the client system administrator. A defect was released to production that…


CPSEC-1: Product Line Test Variables

October 20, 2018

This vulnerability applied to customers who did not changed their default passwords. If passwords were changed from the default, this vulnerability will…


CPSEC-3: Default admin password based on MAC address

October 20, 2018

This vulnerability applied to customers who have not changed their default passwords. If the default password was changed, this vulnerability has a minimal…