CVE Tools

NR17

48 CVEs tracked. None of them is in CISA KEV.

This hub aggregates every CVE we track for NR17, a product in the ics ot iot space. Use it to gauge the current risk picture and drill into individual advisories.

NR17 CVEs per month

Oct 2024 to Sep 2026. Point at a month, or focus the strip and use the arrow keys.
NR17 CVEs per month
MonthCVEs
2024-100
2024-110
2024-121
2025-012
2025-021
2025-030
2025-040
2025-052
2025-061
2025-070
2025-080
2025-093
2025-100
2025-112
2025-123
2026-015
2026-026
2026-031
2026-040
2026-050
2026-060
2026-070
2026-080
2026-090

Severity

How the 48 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.

  • Critical510%
  • High2042%
  • Medium2348%

Latest CVEs

The 15 most recently published vulnerabilities affecting NR17.

  1. CVE-2026-20434In Modem, there is a possible out of bounds write due to a missing bounds check. This could lead to remote escalation of privilege, if a UE has connected to a rogue base station controlled by the a...7.5
  2. CVE-2026-20406In Modem, there is a possible system crash due to an uncaught exception. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with ...6.5
  3. CVE-2026-20405In Modem, there is a possible system crash due to a missing bounds check. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with...6.5
  4. CVE-2026-20404In Modem, there is a possible system crash due to improper input validation. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, w...6.5
  5. CVE-2026-20403In Modem, there is a possible system crash due to a missing bounds check. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with...6.5
  6. CVE-2026-20422In Modem, there is a possible system crash due to improper input validation. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, w...6.5
  7. CVE-2026-20420In Modem, there is a possible system crash due to incorrect error handling. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, wi...6.5
  8. CVE-2025-20760In Modem, there is a possible read of uninitialized heap data due to an uncaught exception. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by ...6.5
  9. CVE-2025-20761In Modem, there is a possible system crash due to incorrect error handling. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, wi...6.5
  10. CVE-2025-20762In Modem, there is a possible system crash due to incorrect error handling. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, wi...6.5
  11. CVE-2025-20793In Modem, there is a possible system crash due to incorrect error handling. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, wi...6.5
  12. CVE-2025-20794In Modem, there is a possible system crash due to improper input validation. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, w...6.5
  13. CVE-2025-20752In Modem, there is a possible system crash due to a missing bounds check. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with...6.5
  14. CVE-2025-20758In Modem, there is a possible system crash due to an uncaught exception. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with ...4.9
  15. CVE-2025-20754In Modem, there is a possible system crash due to an incorrect bounds check. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, w...5.3

Product grouping is registry-driven, with AI assist and human review. How it works

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store