Vulnerability Description
Secutech RiS-11, RiS-22, and RiS-33 devices with firmware V5.07.52_es_FRI01 allow DNS settings changes via a goform/AdvSetDns?GO=wan_dns.asp request in conjunction with a crafted admin cookie.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Secutech Project | Ris-11 Firmware | 5.07.52_es_fri01 |
| Secutech Project | Ris-11 | - |
| Secutech Project | Ris-22 Firmware | 5.07.52_es_fri01 |
| Secutech Project | Ris-22 | - |
| Secutech Project | Ris-33 Firmware | 5.07.52_es_fri01 |
| Secutech Project | Ris-33 | - |
Related Weaknesses (CWE)
References
- https://www.exploit-db.com/exploits/44393/ExploitThird Party AdvisoryVDB Entry
- https://www.exploit-db.com/exploits/44393/ExploitThird Party AdvisoryVDB Entry
FAQ
What is CVE-2018-10080?
CVE-2018-10080 is a vulnerability with a CVSS score of 8.6 (HIGH). Secutech RiS-11, RiS-22, and RiS-33 devices with firmware V5.07.52_es_FRI01 allow DNS settings changes via a goform/AdvSetDns?GO=wan_dns.asp request in conjunction with a crafted admin cookie.
How severe is CVE-2018-10080?
CVE-2018-10080 has been rated HIGH with a CVSS base score of 8.6/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2018-10080?
Check the references section above for vendor advisories and patch information. Affected products include: Secutech Project Ris-11 Firmware, Secutech Project Ris-11, Secutech Project Ris-22 Firmware, Secutech Project Ris-22, Secutech Project Ris-33 Firmware.