{"record":"Deutsche Telekom evidence record","url":"https://nexalign.io/vendors/deutsche-telekom","vendor":{"slug":"deutsche-telekom","name":"Deutsche Telekom","domain":"telekom.de","category":"cloud","categoryLabel":"Cloud and sovereign cloud"},"lastChecked":"2026-07-17T16:20:30.969Z","coverage":{"earliest":"2007-05-14T21:00:00.000Z","latest":"2026-07-17T16:20:30.969Z"},"terms":{"isRanking":false,"isRating":false,"statesSuitability":false,"note":"This is a record of what public sources hold about a named company. It states no ranking, no rating and no suitability verdict, and none may be derived from it. An absent or small record means the public registers publish little under that name; it is not evidence that a product is secure. A larger advisory count generally reflects wider deployment and more scrutiny rather than a weaker product.","licence":"https://nexalign.io/vendors#licence","corrections":"info@nexalign.io"},"totals":{"evidenceItems":17,"kindsOfSource":4,"attributedAdvisories":2,"knownExploited":0,"registerEntriesNotAttributable":2,"practitionerThreads":6,"independentItems":4,"vendorPublishedItems":0,"shareFromSourcesTheVendorDoesNotControl":1},"sources":[{"source":"European Vulnerability Database","operator":"ENISA, European Union","classification":"authoritative","items":4,"latest":"2026-03-10T00:00:00.000Z"},{"source":"National Vulnerability Database","operator":"NIST, United States Department of Commerce","classification":"authoritative","items":2,"latest":"2026-03-10T18:18:01.740Z"},{"source":"Engineering discussions","operator":"Hacker News, public threads","classification":"independent","items":6,"latest":"2026-04-19T00:36:38.000Z"},{"source":"Analyst, review and reference sources","operator":"Recognised analysts, review marketplaces and technology press","classification":"independent","items":5,"latest":"2026-07-17T16:20:30.969Z"}],"advisories":{"shown":2,"total":2,"truncated":false,"items":[{"id":"CVE-2025-69615","description":"Incorrect Access Control via missing 2FA rate-limiting allowing unlimited brute-force retries and full MFA bypass with no user interaction required.","severity":"critical","cvss":9.1,"knownExploited":false,"date":"2026-03-10T18:18:01.740Z","sources":["https://nvd.nist.gov/vuln/detail/CVE-2025-69615","https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-208508"]},{"id":"CVE-2025-69614","description":"Incorrect Access Control via activation token reuse on the password-reset endpoint allowing unauthorized password resets and full account takeover.","severity":"critical","cvss":9.4,"knownExploited":false,"date":"2026-03-10T18:18:01.610Z","sources":["https://nvd.nist.gov/vuln/detail/CVE-2025-69614","https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-208506"]}]},"practitionerThreads":{"shown":5,"total":6,"truncated":true,"items":[{"title":"Deutsche Telekom has a bad DKIM key","context":"Hacker News","url":"https://news.ycombinator.com/item?id=47820806","date":"2026-04-19T00:36:38.000Z"},{"title":"Meta unit must pay Deutsche Telekom $36M over network services, German court say","context":"Hacker News","url":"https://news.ycombinator.com/item?id=47001490","date":"2026-02-13T11:18:20.000Z"},{"title":"Deutsche Telekom is throttling the internet","context":"Hacker News","url":"https://news.ycombinator.com/item?id=46751899","date":"2026-01-25T08:22:17.000Z"},{"title":"Nvidia and Deutsche Telekom Partner to Advance Germany's Sovereign AI","context":"Hacker News","url":"https://news.ycombinator.com/item?id=44274786","date":"2025-06-14T07:20:38.000Z"},{"title":"How Deutsche Telekom Makes Cloudflare Re-Route Traffic Around the Globe","context":"Hacker News","url":"https://news.ycombinator.com/item?id=43158371","date":"2025-02-24T11:38:07.000Z"}]},"independentCoverage":{"shown":4,"total":4,"truncated":false,"items":[{"title":"Deutsche Telekom Enterprise Software and Services Reviews","host":"gartner.com","url":"https://www.gartner.com/reviews/vendor/deutsche-telekom","date":null},{"title":"Deutsche Telekom - Wikipedia","host":"en.wikipedia.org","url":"https://en.wikipedia.org/wiki/Deutsche_Telekom","date":null},{"title":"Deutsche Telekom Global WAN Services Reviews, Ratings & Features 2026 | Gartner Peer Insights","host":"gartner.com","url":"https://www.gartner.com/reviews/market/global-wan-services/vendor/deutsche-telekom/product/deutsche-telekom-global-wan-services","date":null},{"title":"Deutsche Telekom Reviews, Ratings & Features 2026 | Gartner Peer Insights","host":"gartner.com","url":"https://www.gartner.com/reviews/market/global-enterprise-mobile-services/vendor/deutsche-telekom","date":null}]},"vendorPublished":{"shown":0,"total":0,"truncated":false,"items":[]},"openQuestions":["A further 2 register entries mention Deutsche Telekom without naming a product of Deutsche Telekom as affected. They are excluded rather than counted as vulnerabilities.","Pricing, contract terms, notice periods and support commitments are not part of any public register. They come from the vendor and belong in a negotiation record.","Certification status such as ISO 27001, SOC 2 or BSI C5 has to be checked against the current certificate and its stated scope. A valid certificate can still exclude the product being bought."]}